Advanced features
High Availability and Load Balancing
The SafeMove server can be deployed on a single server, or as a highavailability/load-balanced cluster of up to eight servers running RedHat EnterpriseLinux. The dynamic load-balancing capability maintains an even load across all available servers. And because the stateful IKE and IPSec security associations are shared within the cluster, the resulting lossless failover is totally transparent to users. The SafeMove server also supports multiple Home Agents in both distributed and clustered configurations to further enhance fault tolerance and eliminate potential bottlenecks. As with the clients, SafeMove server software is upgraded and reconfigured as necessary using SafeMove Manager.
Hot Spot Login Assistant
The SafeMove Hot Spot Login Assistant makes it easy for end users to utilize a public Wi-Fi Hot Spots by making all of the IPSec and Mobile IP connections automatically after logging into the HotSpot via the browser. If a Wireless WAN connection is available while performing the Hot Spot login, the user’s connection to enterprise network is retained using the Wireless WAN while the Hot Spot login process is active and automatically transferred to utilize Wi-Fi connection once the Wi-Fi authentication is completed. Unlike many other VPN solutions, which require turning VPN manually off upon Hot Spot login and then back on again after login, SafeMove takes care of the mobile host’s security also during the Hot Spot login procedure and requires no user intervention to deactivate/activate the VPN nor the inbuilt personal firewall.
Anti-virus Quarantine
The Anti-virus Quarantine feature detects when a laptop’s anti-virus software or virus definitions are not up-to-date, and sets the personal firewall to a quarantine state that blocks access to the enterprise network. In this condition, the user is permitted access only to the server used for updating anti-virus software and definitions. Once the remedies have been applied, the user is automatically allowed to access the enterprise network again.
Intranet Detection
The optional intranet detection feature of SafeMove recognizes when the user connects via the private enterprise network, securely inside the firewall, and disables tunneling and encryption in the client to improve throughput performance.