SSL/VPN remote access provides Avaya and Avaya partners with reliable remote access that enhances service delivery while reducing the cost associated with truck rolls. The solution enables partners of any size to create an infrastructure that automates management and maintenance of IP Office systems.
IP Office software includes an embedded SSL/VPN client. On the server side (should the partner decide to host the server side), the partner will need to install a server (VM) and install the Avaya VPN Gateway (AVG) software. The Partner will establish the SSL/VPN Gateway configuration on the IP Office so that the IP Office can trigger a secure tunnel back to the Gateway.
A username/password is setup during the configuration step for security purposes. A second level of security is also provided with a server-side certificate authentication. A radius server will then validate the username/password upon connection request initiated from the IP Office. Once the credentials are validated, the secure remote access is established.
At a minimum, the partner needs to ensure that a broadband connection is available at the customer site. A partner deciding to host the server side can purchase (scale as you go) the SSL/VPN licenses based on how many simultaneous connections are required. The AVG software is installed on a VM server software (the partner can choose the server of their choice) and set up a radius server for username/password authentication. The same VM server can also act as a radius server or the partner can use a separate radius server or reuse an existing radius server based on their IT department's recommendations and security policy.
Partners wanting to host the server side gateway should refer to the Avaya enterprise portal for more detailed information about the Avaya VPN gateway solution (see https://enterpriseportal.avaya.com/ptlWeb/gs/products/P0623/AllCollateral).
SSL/VPN remote access provides the following functionality:
Secure remote access at broadband speeds for enhanced support
Simple configuration and deployment
Scaling to accommodate future growth requirements
Networking expertise not required at the customer site (No IT admin required at the customer site)
No requirement to open holes in the firewall (Firewall-agnostic as the connection is initiated from the customers' site to the Gateway)
Connection can be Always-ON
or can be initiated via Dial-Up or Phone.
Facilitation of remote configuration, management, monitoring, diagnostics, and upgrades.