Secure Configuration
Verification
VPN-1
SecureClient provides the basic user
authentication and encryption capabilities of
VPN-1 SecuRemote, plus additional features, such
as powerful Security Configuration Verification
(SCV). SCV Checks enhance network security by
ensuring that only securely configured clients
are connected to the corporate VPN.
-
Secure Configuration
Verification
-
Software Version
Control
-
Application Usage
Control
-
Enhanced Access
Control
-
Custom SCV Checks
-
Logging & End-user
Notification
Secure Configuration Verification
VPN-1 SecureClient
strengthens enterprise security by ensuring that
only securely configured client machines are
connected to the corporate VPN.
Administrators do this by defining Secure
Configuration Verification (SCV) checks - a set
of conditions that define a securely configured
client system - such as the current version of
anti-virus and browser software. SCV checks are
performed when the client attempts to connect to
the VPN, and regularly during a VPN session.

Administrators can apply
pre-defined or custom SCV checks.
Software Version Control
Protect your network with
the following pre-defined SCV checks that ensure
clients are running the right version of
software:
-
Operating System (OS)
Monitor verifies
OS version, service pack and screen saver
configuration
-
HotFix Monitor
verifies OS security patches are installed
-
Browser Monitor
verifies browser version
Application Usage Control
Ensure that
specific programs, such as those for anti-virus,
are running and configured to your
specifications, or restrict usage of programs,
such as Kazaa, with the following pre-defined
SCV checks:
-
Process Monitor
verifies that a specific process is or is
not running
-
Version Checker
verifies VPN-1 SecureClient version
-
OPSEC SCV Checks
from OPSEC application vendors - including
Norton, Okena, Pestpatrol, Trend Micro and
TripWire - have created downloadable SCV
checks that provide you with centralized
control of locally deployed applications
-
NEW!
Registry Checker verifies parameter
settings for applications running on Windows
machines
Enhanced Access Control
Apply the
following pre-defined SCV checks for stronger
security through enhanced access control:
-
CPU Checker
verifies VPN-1 SecureClient has not been
reinstalled on a different machine
-
Group Monitor
verifies that a user belongs to a specific
Domain User group

Click for larger image
Pre-defined SCV checks such
as the OS Monitor strengthen enterprise
security.
Custom SCV Checks
Administrators can write
custom SCV checks through an SCV editor. You can
even have the client download and run a .bat or
.exe script as an SCV check.
Logging & End-User
Notification
When clients do not meet SCV
criteria, you can automatically send an
instructional message in a pop-up box to the
end-user. In addition, you can send a log to the
VPN-1/FireWall-1 SecureClient log file.