The IC6500 Unified Access Control Appliance is the next generation of hardened, centralized network access policy management servers, delivering scalability, performance, and redundancy.
Designed to address the network access needs of large multi-national organizations and government agencies, the IC6500 network access server scales to support up to 15,000 simultaneous endpoint devices. This network access server can be deployed standalone or in three-unit clusters to increase performance and provide additional scalability, supporting up to 30,000 simultaneous endpoint devices. The IC6500 network access server includes redundant, field-upgradable, high-availability features, including:
The IC6500 network access server, through the Unified Access Control Agent or UAC agent-less mode, can gather user authentication, endpoint security state, and device location data, in order to define dynamic network access policies that it distributes to enforcement points across the network. These network access enforcement points can include any vendor-independent 802.1X-enabled access point and switch, such as EX Series Ethernet Switches, and any Juniper Networks firewall platform, including SSG Series Secure Services Gateways and ISG Series Integrated Security Gateways with Intrusion Detection and Prevention, as well as the robust networking and security services of SRX Series Services Gateways.
User session data can be shared between the IC6500 network access server and SA Series SSL VPN Appliances, enabling the seamless provisioning of SSL VPN user sessions into UAC upon login, or alternatively UAC user sessions into SSL VPN at login. Also, users authenticated to one IC6500 network access server may, if authorized access resources protected by another IC Series appliance on the network, enabling "follow-me" policies. UAC leverages the TNC standard protocol IF-MAP to enable this federation of user session data, providing users—whether remote or local— with seamless access to corporate resources protected by uniform network access control policies through a single login.
The IC6500 network access server offers the following additional hardware and software options:
| Options | Option Description |
|---|---|
| Microsoft SOH Licenses | Addresses the licensing of the Microsoft System Health Agent (SHA)/System Health Verifiers (SHV) and Statement Of Health (SOH) protocols, which are key to supporting the Microsoft Windows SOH and embedded Microsoft Network Access Protection (NAP) Agents through the TNC SOH open, standard protocol. |
| IF-MAP Licenses | Leveraging the TNC's IF-MAP specification, an IC Series Appliance (or IC Series Appliance cluster) operating solely as a MAP server with no additional simultaneous endpoint licenses or OAC-ADD-UAC licenses must have an IF-MAP license installed. An IC Series Appliance (or IC Series Appliance cluster) operating simultaneously as an IC Series Appliance and as a MAP server, with a simultaneous endpoint license or an OAC-ADD-UAC license installed does not require an IF-MAP license. |
| Unified Access Control Disaster Recovery (DR) Licenses | Unified Access Control Disaster Recovery licenses address network disaster situations, but don't require a permanent purchase of user licenses for disaster contingencies. Unified Access Control Disaster Recovery licenses also provide the ability to test disaster recovery deployment while providing usage when needed. Unified Access Control Disaster Recovery licenses are also available for clusters. |
| Coordinated Threat Control Licenses | Additional access control and security capabilities are available with Juniper Networks IDP Series Intrusion Detection and Prevention Appliances for coordinated threat control. |
| Hot-Swappable Power Supplies | The IC6500 network access server offers optional dual, hot-swappable power supplies. |
Technical Support:
Awards and Recognition:
Certification and Training:
|
| Model Number | Description |
|---|---|
| Base System | |
| IC6500 | IC6500 Base System |
| Endpoint Licenses | |
| IC6500-ADD-100E | Add 100 simultaneous endpoints to IC6500 |
| IC6500-ADD-250E | Add 250 simultaneous endpoints to IC6500 |
| IC6500-ADD-500E | Add 500 simultaneous endpoints to IC6500 |
| IC6500-ADD-1000E | Add 1,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-2000E | Add 2,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-3000E | Add 3,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-5000E | Add 5,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-10000E | Add 10,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-15000E | Add 15,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-20000E | Add 20,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-25000E | Add 25,000 simultaneous endpoints to IC6500 |
| IC6500-ADD-30000E | Add 30,000 simultaneous endpoints to IC6500 |
| Feature Licenses | |
| IC6500-OAC-ADD-UAC | Allows Odyssey Access Client Enterprise Edition clients to be converted to Odyssey Access Client UAC Edition clients and used with an IC6500 |
| Clustering Licenses | |
| IC6500-CL | Add clustering on IC6500 |
| IC6500-CL-500E | Allow clustering to another IC6500 licensed for up to 500 endpoints |
| Coordinated Threat Control Licenses | |
| IC6500-ADD-TCTRL | Add Coordinated Threat Control with IC6500 and Juniper Networks IDP Series appliances |
| Disaster Recovery (DR) Licenses | |
| IC6500-DR | IC6500 DR Licenses (Allows bursting to full concurrent user capacity of IC6500 for up to eight weeks) |
| IC6500-DR-CL | IC6500 Cluster DR License (To cluster another IC6500 to a primary for disaster recovery) |
| Statement of Health (SOH) Licenses | |
| IC6500-SOH | Adds Microsoft SOH/NAP Agent integration capabilities to the IC6500 |