667
Nortel WLAN—Security Switch 2300 Series Configuration Guide

Configuring SODA endpoint security

for a WSS

Sygate On-Demand (SODA) is an endpoint security solution that allows enterprises to enforce security policies on client
devices without having to install any special software on the client machines. WSS Software can be configured to run
SODA security checks on users’ machines as a requirement for gaining access to the network.

About SODA endpoint security

The SODA endpoint security solution consists of six modules that provide on-demand security:
Virtual Desktop – Protects confidential data by virtualizing the desktop, applications, file-system, registry,
printing, removable media, and copy/paste functions. All data is encrypted on-the-fly and can optionally be erased
upon session termination. The virtual desktop is isolated from the normal desktop, protecting the session from
previous infection.
Host Integrity – Tests the security of the desktop to determine how much access to network resources the device
should be granted. Host integrity checks include:
Ensuring that an anti-virus product is running with up-to-date virus definitions
Ensuring that a personal firewall is active
Checking that service pack levels are met
Ensuring that critical patches are installed.
Custom checks can be implemented based on the existence of specific registry keys/values, applications,
files, or operating system platforms. Network access can also be prevented based on the existence of
specific processes.
Malicious Code Protection – Detects and blocks keystroke loggers that capture usernames and passwords, Trojans
that create back-door user accounts, and Screen Scrapers that spy on user activity.
The Malicious Code module integrates a Virtual Keyboard function that requires users to input
confidential information such as passwords using the Virtual Keyboard when accessing specific Web
sites, to protect against hardware keystroke loggers. This module uses a combination of signatures for
known exploits and behavioral detection to protect against unknown threats.
Cache Cleaner – Ensures that Web browser information, such as cookies, history, auto-completion data, stored
passwords, and temporary files are erased or removed upon termination of the user’s session, inactivity timeout, or
closing of the browser.

About SODA endpoint security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 667

Configuring SODA functionality . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 670