Platforms Guide Junos Pulse Platforms Release 4.0 R1 Juniper Networks, Inc. 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408 745 2000 or 888 JUNIPER www.juniper.net February 2013 Copyright 2010, Juniper Networks, Inc.
Contents Introduction... 1 Definitions... 1 Qualified Platform... 1 Compatible Platform... 1 Related Documents... 1 Hardware Requirements... 1 Server Compatibility Matrix... 2 Hardware Support... 2 Server OS Compatibility Matrix... 2 Client Compatibility Matrix... 2 Qualified platforms... 2 Compatible platforms... 2 Multiple Language Support... 4 Adaptive Delivery for Juniper Client Applications... 4 Junos Pulse deployed as Host Checker Policy... 4 Junos Pulse Access Methods Matrix... 5 Interoperability... 7 Juniper Client Interoperability... 7 3rd Party Client Interoperability... 8 [ii]
Junos Pulse 4.0 R1 Platforms Guide Introduction Junos Pulse is a dynamic, integrated network client. A core component of Junos Platform, Junos Pulse delivers integrated, anytime/anywhere connectivity, acceleration, and security, while drastically simplifying user experience. With Junos Pulse, users no longer need to interact with network access and security software. Definitions Qualified Platform The platforms listed in the qualified category have been systematically tested by Juniper Networks Quality Assurance department as part of the release. Compatible Platform The platforms listed in the compatible category have not been systematically tested by our QA department in this release but are based on testing in previous releases and knowledge of the platform Juniper Networks expects that the functionality will work and will fully support these platforms. Related Documents Junos Pulse Secure Access Service Platform Guide (7.4) Junos Pulse Access Control Service Platform Guide (4.4) Junos Pulse Migration Guide Junos Pulse Administration Guide Hardware Requirements Junos Pulse client will run on any client endpoint that has the following minimum configuration. CPU Intel / AMD, 1.8GHz, 32-bit (x86) or 64-bit (x64) processor System Memory 2 GB RAM Disk Space Install: 25 MB Logging: 50 MB Networking 10/100/1000 Wired Ethernet, 802.11 b/g/n Wi-Fi [1]
Junos Pulse 4.0 R1 Platforms Guide Server Compatibility Matrix Hardware Support Please refer to the SA or IC supported platform doc for the hardware support. e: FIPS platforms in the SA and IC Series do NOT run in FIPS mode since Junos Pulse does not incorporate FIPS functionality Server OS Compatibility Matrix Product Qualified Compatible Junos Pulse Secure Access Series Junos Pulse Access Control Series IVE 7.4R1, IVE 7.3R1 and IVE 7.2R5 C4.4R1, C4.3R1 and C4.2R5 IVE 7.1 Rx, IVE 7.0Rx C4.1Rx, C4.0Rx SRX JUNOS 12.1R2.9 and 11.4R3.7 11.x, 10.x APP ACCEL JWOS 6.2R1.4 JWOS 6.1.R2.1 Older versions of Pulse client like (Pulse 2.1 / Pulse 2.0 / Pulse 1.0) can also be used against the IVE 7.2 but the new features which are added post the release of the respective client will not be available. For example a Pulse 2.0 / Pulse 2.1 can have all the features of IVE 7.1 working against IVE 7.2 but the newly added features like ESP support etc. in IVE 7.2 / Pulse 3.0 will not be available when using Pulse 2.1/ Pulse 2.0. Client Compatibility Matrix Qualified platforms Platform Operating System Browsers and Java Environment Windows MAC Windows 7 SP1 Enterprise 64-bit Windows 8 Enterprise 64-bit Mac OS X 10.7.3, 64 bit Mac OS X 10.8, 64 bit Internet Explorer 8.0 (with Win XP) 9.0, 10 (only with Win 8) Firefox ESR Oracle JRE 7 Safari 5.1 Oracle JRE 7 (with 10.7.3) Safari 5.2 Oracle JRE 7 (with 10.8) Compatible platforms Platform Operating System Browsers and Java Environment [2]
Junos Pulse 4.0 R1 Platforms Guide Windows 1 Windows 7 Ultimate/Professional/Home Basic/Home Premium on 32-bit or 64-bit platforms Windows 8 normal-edition/pro on 32-bit or 64-bit platforms Windows 8 Enterprise 32-bit platforms Internet Explorer 8.0 Internet Explorer 7.0 Firefox 3.0 and above Oracle JRE 6 and above Vista Ultimate/Business/Home-Basic/Home- Premium with Service Pack 2 on 32-bit or 64-bit platforms XP Home with SP3 (32-bit only) (IPv6 features are not supported) XP Professional SP3 32-bit (IPv6 features are not supported) Mac OS X 10.6.8, 32 bit Mac OS X 10.7.3, 32 bit Mac OS X 10.8, 32 bit 1 Junos Pulse is not supported on Windows Server platforms and Linux Platforms. Smart Cards and Soft tokens Matrix Qualified Cards Cards Software Version Aladin etoken PKI client version 5.1 and Drivers version of 5.1 Safnet ikey 2032 PKI client version 7.0.8.0022 and Driver version v 4.0.0.20 Gemalto.Net cards Driver version 2.1.3.210 Qualified Soft token RSA Application version 4.1.0.458 Server RSA Authentication Manager 7.1. Client RSA SecurID Software Token All the above mentioned smart cards are qualified on all the below mentioned qualified platforms matrix. [3]
Junos Pulse 4.0 R1 Platforms Guide Qualified platforms Platform Windows Operating System XP Professional SP3 32-bit Windows 7 Enterprise 64-bit Windows 8 Enterprise 64-bit Multiple Language Support The Junos Pulse client software and online help has been localized in German, French, Japanese, Traditional Chinese, Simplified Chinese, Spanish, and Korean. The administrator user interface is supported in English only. The administrator guide is published in English and Japanese. Adaptive Delivery for Juniper Client Applications In cases where ActiveX is disabled or is not available due to platform or privilege limitations, the client application is installed using Java. Adaptive delivery is available for Junos Pulse (including other legacy clients like WSAM, Network Connect, Windows Terminal Services, and Secure Meeting). Sun JRE 1.6 Update 12 or greater must be installed on the client system to utilize adaptive Delivery for Juniper client applications. Junos Pulse deployed as Host Checker Policy Junos Pulse client may also be deployed as a remediation host checker policy. This channel is only supported for standalone Junos Pulse Application Acceleration service working in conjunction with pre-7.0 Network Connect clients. It is meant to provide a transition path for customers using the standalone APP ACCEL client (now discontinued). Qualified SA6500 running 6.5 R2 on Windows XP-SP3 Professional 32-bit Windows 7 SP1 Enterprise 64-bit SA6500 with IVE version 7.0 R1 or 7.1 or 7.2 or on Windows XP-SP3 Professional Windows 7 Enterprise. Compatible Any SA device running 6.3, 6.4, 6.5, 7.0, 7.1 and 7.2 on Windows XP-SP3 Home Vista-SP2 Home Basic, Home, Professional, Ultimate Windows 7 Home, Home Basic, Ultimate [4]
Junos Pulse 4.0 R1 Platforms Guide Junos Pulse Access Methods Matrix Junos Pulse provides 5 different basic access methods (NC, WSAM, UAC, FWAM and AppAccel). Additionally in some cases it supports multiple connections of the same type, connectivity at L2/L3 over wired/wireless, with and without enforcement or acceleration. As such the universe of possible combinations of connections is vast. Following table lists the configurations that are supported and qualified by QA. PNC Junos Pulse NC Access Method PUAC Junos Pulse UAC Access Method FWAM Junos Pulse Firewall Access Method for connecting to JUNOS SRX platforms a.k.a Dynamic VPN AppAccel Junos Pulse App Accel Method. Configuration Description Comments PUAC inside PNC outer tunnel AppAccel+PUAC inside PNC outer tunnel PUAC inside PNC outer tunnel + FWAM PUAC (L2/L3) + PUAC(L3) PUAC + FWAM Junos Pulse L3 UAC Source-IP or IPsec enforcement over Junos Pulse NC (TLS) remote access tunnel Application accelerated connection controlled by UAC enforcement point, coming over a Junos Pulse NC Remote access tunnel Junos Pulse L3 UAC Source-IP or IPsec enforcement over Junos Pulse NC remote access (TLS) to an SA device, running in parallel with FWAM IPsec connection to another SRX device. Junos Pulse L2 or L3 UAC enforcement to an Infranet Controller, running in parallel with a Junos Pulse L3 UAC enforcement tunnel to another Infranet controller (i.e. multiple standalone UAC connections) Junos Pulse UAC enforcement tunnel to one SRX device running in parallel with FWAM IPSEC connection to another SRX device. Any other combinations not mentioned here are not supported. Qualified Qualified Compatible Qualified Compatible Pulse IC IPsec enforcement in Pulse SA (TLS) tunnels is supported. All other nested tunnel operations in any combination (NC/NC, UAC/UAC or FWAM/FWAM) are not supported. For Nested tunnels support for PNC Outer Tunnel and PUAC Inner Tunnel here are the settings matrix that is supported: The following are the configurations that are supported in the case of Tunnel inside Tunnel SA (Outer Tunnel) with IC (Inner Tunnel). The way to read this table is use the SA settings as reference and for those settings of SA the supported settings of IC are mentioned as YES. Whatever configuration says NO in IC is NOT supported. This table is only for Pulse 3.1 with 7.2 SA and 4.2 IC settings only and NO legacy components involved. [5]
Junos Pulse 4.0 R1 Platforms Guide SA with SSL mode: SA (SSL Mode only) IC Mode Route Override Route Monitor IPsec (with VA) IPsec (without VA) Dynamic IPsec* Source IP Dynamic Source IP Disable Split Tunneling No No Disable Split Tunneling No No Enable Split Tunneling No Enable Split Tunneling * Dynamic IPsec is not supported in SRX. (IC IP address, IE IP address, and IC VA pool address should be added in Pulse NC split tunneling network) (IC IP address, IE IP address, and IC VA pool address should be added in Pulse NC split tunneling network) (protected resource should be added in Pulse NC split tunneling network and SA should have a route to IC protected resource) No (protected resource should be added in Pulse NC split tunneling network and SA should have a route to IC protected resource) No [6]
Junos Pulse 4.0 R1 Platforms Guide SA with ESP Mode: Mode Disable Split Tunneling Disable Split Tunneling Enable Split Tunneling Enable Split Tunneling SA Route Precedence Tunnel Routes Tunnel Routes Tunnel Routes Tunnel Routes Route Monitor No No IPsec (with VA) IPsec (without VA) IC Dynamic Source Dynamic IPsec* IP Source IP e: SA in WSAM mode works in Silos and does not interoperate in conjunction with IC or App Acceleration product. Interoperability Install Coexistence: Both products can be installed on the same machine at the same time. ONLY 1 product is active at any time. Runtime Coexistence: Both products can be installed and running at the same time. Juniper Client Interoperability Product Version Co-existence Nested Tunnel Operation Juniper Network Connect 7.4 Install Limited Support - see Access Methods Matrix Juniper Network Connect 6.3, 6.4, 6.5, 7.0, 7.1, 7.2, 7.3 Juniper Odyssey Access Client (OAC) Juniper Odyssey Access Client (OAC) Install 5.5 and 5.6 (or UAC 4.4) Install OAC 802.1x in L2 with Pulse 3.1 in L3 is supported. No other combinations are supported. Pre-5.4 (or UAC pre-4.2) supported (installation will abort) Juniper WSAM/JSAM Any Install Juniper Secure Meeting Client Juniper (Netscreen) NSRemote Client Any Install Any Install [7]
Junos Pulse 4.0 R1 Platforms Guide Juniper Access Manager (Dynamic VPN Client) Juniper Standalone WXC client 1.0 (installation will abort) Any 3rd Party Client Interoperability Product Version Coexistence Nested Tunnel Operation Cisco VPN 3000 Concentrator with Junos Pulse (non-app ACCEL) Nortel Contivity Server 1010 with Junos Pulse (non-app ACCEL) Cisco ASA 5505 with Junos Pulse (non-app ACCEL) Cisco VPN 3000 Concentrator with Junos Pulse (using only APP ACCELAM) Nortel Contivity Server 1010 with Junos Pulse (using only APP ACCELAM) Cisco ASA 5505 with Junos Pulse (using only APP ACCELAM) Checkpoint CP Secure Remote Server Version: 4.1.7 D 4.6.04.0043 (Win XP SP3) 5.0.07.0290 (Win 7 64-Bit) Server Version: V04_80.124 V06_01.109 (Win XP SP3) Server Version: 8.0(3) 4.6.04.0043 (Win XP SP3) 5.0.07.0290 (Win 7 64-Bit) Server Version: 4.1.7 D 4.6.04.0043 (Win XP SP3) 5.0.07.0290 (Win 7 64-Bit) Server Version: V04_80.124 V06_01.109 (Win XP SP3) Server Version: 8.0(3) 4.6.04.0043 (Win XP SP3) 5.0.07.0290 (Win 7 64-Bit) NGX R60 HFA2(Build 002) (Win XP SP3) Install Install Install Runtime Runtime Runtime Install applicable applicable applicable [8]
Junos Pulse 4.0 R1 Platforms Guide [9]