Forefront Unified Access Gateway 2010 delivers comprehensive, secure remote access to corporate resources for employees, partners, and vendors on both managed and unmanaged PCs and mobile devices. Utilising a combination of connectivity options, ranging from SSL VPN to DirectAccess, as well as built in configurations and policies, UAG provides centralised and easy management of an organisation's complete anywhere access offering.

 
Get the Datasheet Download an Appliance
 
Are you running an IAG appliance from another vendor? Is the hardware running out of steam or costing too much to maintain? Looking to the latest Forefront platform on industry standard hardware? Upgrade or Trade-up today!

Integrating a deep understanding of the applications published, the state of health of the devices being used to gain access, and the user's identity – UAG enforces granular access controls and policies to deliver comprehensive remote access, ensure security, and reduce management costs and complexity.

  • Remote Access to SharePoint and/or Exchange. Optimised for SharePoint and Exchange, UAG delivers secure, anywhere access for your employees, partners and customers. Leveraging a combination of granular application filtering capabilities, deep endpoint health detection and wizard driven configuration—UAG provides for a simple and highly secure means of publishing Exchange and SharePoint deployments.
     

  • Comprehensive Remote Access (SSL VPN). As a comprehensive SSL VPN, UAG provides multiple levels of access and tunneling to deliver internal applications and network resources to remote users.
     

  • DirectAccess. UAG extends the benefits of DirectAccess across the infrastructure, enhances scalability, and simplifies deployment and ongoing management.

DirectAccess Performance and Scalability
DirectAccess is very resource intensive and performance statistics should not be confused with typical UAG web portal usage scenario user volumes. When deciding on hardware for DirectAccess it is important that your hardware supports Receive Side Scaling Queues (RSS) as Microsoft estimates that approximately 30% greater capacity is achievable on RSS enabled systems. All Winfrasoft Appliances support RSS natively.

The following table shows the approximate maximum  number of concurrent DirectAccess users for each appliance model based on typical usage scenarios. These numbers are not hard limits, each appliance can physically accept more connections at the expense of overall performance.

UAG Appliance Model Approx concurrent Direct Access users Receive Side Scaling Queues (RSS) support
UAG-1500 200 users Yes (Port 1 only)
UAG-3500 500 users Yes (All Ports)
UAG-6500 1,000 users Yes (All Ports)
UAG-9500 2,500 users Yes (All Ports)

See http://technet.microsoft.com/en-us/library/ff723731.aspx for further information.


Leverage DirectAccess

DirectAccess is a new feature in the Windows® 7 and Windows Server® 2008 R2 operating systems that gives users the experience of being seamlessly connected to their corporate network any time they have Internet access. With DirectAccess, users are able to access corporate resources (such as e-mail servers, shared folders, or intranet Web sites) following common security standards, anytime they have an internet connection.
  • Improve Productivity of Mobile Workforce. DirectAccess provides increased productivity for your mobile workforce by offering the same connectivity experience both in and outside of the office. DirectAccess is on whenever the user has an Internet connection, giving users access to intranet resources whether they are traveling, at the local coffee shop, or at home.
     

  • Improved Manageability of Remote Users. Without DirectAccess, mobile computers can only be managed when users connect to a VPN or physically enter the office. With DirectAccess, mobile computers can be managed any time the mobile computer has Internet connectivity, even if the user is not logged on. This allows remote computers to be managed regularly and helps ensure mobile users stay up-to-date with security and system health policies. DirectAccess helps ensure that organisations can meet regulatory and privacy mandates for security and data protection for assets that must roam beyond the corporate network.
     

  • Improved security. DirectAccess uses Internet Protocol security (IPsec) for authentication and encryption. Optionally, you can require smart cards for user authentication. DirectAccess integrates with Network Access Protection (NAP) to require that DirectAccess clients must be compliant with system health requirements before allowing a connection to the DirectAccess server. IT administrators can also configure the DirectAccess server to restrict the servers that users and individual applications can access.

Get the datasheet

Compare IAG 2007 vs UAG 2010
Forefront UAG 2010 introduces many new and improved features over its predecessor IAG 2007:
 
  IAG UAG

Application Publishing

   
Granular application filtering √*
Session cleanup and removal
Endpoint health detection √*

Integration

   
Integrated with NAP policies  
Remote Desktop and RemoteApp integration  
Extends and simplifies DirectAccess deployments  

Scale and Management

   
Built in load balancing  
Array management capabilities  
Enhanced monitoring and management (SCOM)  

*Feature is improved in UAG

Pricing
We strive to price our appliances to be highly competitive. From time to time we run special offers for large deployments, to enquire about these please contact us.

Click here to download the full price list



Winfrasoft is featured multiple times on ISAServer.org:
(1) "Product Review: Winfrasoft Gateway Appliances"
(2)
"Releasing VPN Quarantine Users with VPN-Q 2006"
(3) "Winfrasoft's Backup for ISA Server - Filling an Important Gap"
(4) "X-Forwarded-For and the ISA Firewall: Track your Originating Client through a Web-proxy Chain and on Your IIS"


Forefront UAG 2010 highlights


Gateway Appliance Hardware Matrix

UAG Gateway Appliance Datasheet

Microsoft DirectAccess Datasheet

UAG & DirectAccess Whitepaper


"Winfrasoft's choice of hardware platform sets it apart from the competition, as this doesn't lock you in to proprietary solutions with limited or non-existent upgrade paths."


"Winfrasoft's TMG 2010 package is a better choice than Celestix's alternatives as its hardware platforms are industry standard, it can be field-upgraded and comes with a superior warranty."


"There are a lot of choices on the market, but the 9500-DE stands out with its classy hardware platform and superior warranty."

ISAserver.org Gold Award