3 ms·
Do you have more information on these 'protected proxies' that you mention? My understanding was more that it was each client was given a health check of sorts
by darksim905 9y ago
Do you have more information on these 'protected proxies' that you mention? My understanding was more that it was each client was given a health check of sorts & was either allowed, or not allowed after meeting a certain number of criteria.
- gbil 9y agoFor commercial solutions take a look at zscaler offerings. The biggest problem in such solutions is that you have to identify the applications you have and sure Google is a relatively new tech company. Try to identify all apps/services on big old companies. Until you do that or decommission them, hou have either to keep your old VPN solution up or proxy ALL traffic and use the analysis tools they have to identify apps/services, again no walk in the park. Of course as mentioned Google has most of its apps/services anyhow on the Internet so you mostly just use the host checking and client identification functionalities of such tools.
- e12e 9y agoYou could probably keep the vpn and incrementally move services "out", starting with low-hanging fruit (few dependencies) and/or popular ones (eg: (Web)mail). Basically low cost/high benefit trade-off. At some point you'll have a few dinosaurs on the vpn, and can take those services quietly out back and retire them permanently.
- maxsaltonstall 9y agoEach time an employee tries to connect to an application, the access proxy makes an evaluation of how much trust that session can earn, and if it's equal to or greater than the trust required by the application, the proxy allows the traffic through. The trust earning is based on host/machine information as well as user and authentication information.
- wyc 9y agoThis paper should have the most relevant answers to your questions: Beyond Corp: The Access Proxy https://research.google.com/pubs/pub45728.html https://research.google.com/pubs/pub45728.html