Product Overview
A security relay platform that safely connects internal and external networksIt integrates with SHIELDGate and provides a secure access environment without the need for a separate agent.
SHIELD Edge Linkis an on-premises security gateway that connects communications between internal systems and external services more securely and flexibly. It complements the limitations of the existing VPN method and provides everything from user authentication to access control, remote access, remote browsing isolation (RBI), and domain-based DNS policy management on a single platform, based on a zero trust architecture.
**External Request Relay (Inbound)WowInternal Request Relay (Outbound)The configuration is functionally separated and can be operated independently or configured together depending on the customer environment. The product isSingle Image (OVF)**It is provided in the form of __PH_0__, and after installation, you can configure each role through the console.
SHIELD Edge Link Configuration
| Composition | Description |
|---|---|
| Access Control Service | Service providing user authentication-based access control, JWT token validation, and ZTCAP policy application |
| Proxy Relay Service | Service that provides internal ↔ external communication relay and URL access control functionality |
| Remote Access Function | A feature that provides remote access to a desktop or console (SSH) on an internal network PC or server through a browser. |
Relay Proxy Service Details
Proxy Relay Serviceis divided as follows:
- Inbound: A function that mediates requests for external users to access the internal system.
- Outbound: A feature that allows access only to external URLs registered on the internal network.
- The above features are designed to be selectively activated or used together within a single SHIELD Edge server image.
Features and Benefits of SHIELD Edge Link
Providing a secure communication environment without a VPN
SHIELD Edge Link is designed to securely connect internal systems and external environments without complex VPN configurations. Through user authentication, access control, and relay segment encryption,Without VPNYou can also build a stable work environment.
Zero Trust Based Architecture
User authentication through SHIELD ID andZTCAP PolicyBy implementing access control based on verification of all requests, we strengthen the protection of the internal network. By designing security with the premise of 'never trust', unnecessary access can be blocked in advance.
Operational Convenience and Scalability
Agentless Structurecan be used with just a browser without user-side installation, andOVF Image-Based Installationis easy to deploy. Also, IP, DNS, firewall settings, etc. areConsole UIcan be managed directly, making maintenance convenient and expansion flexible from the perspective of IT operators.
Support for both cloud and on-premises
Legacy SystemandCloud Servicecan be integrated with all of them, and in the case of external access, a segregated browsing environment (RBIThrough __PH_0__, it blocks the influx of malware and provides safe external integration.
Main Features
Access Control Service (IAP)
- User Authentication Based Access Control
- JWT Token Verification
- Applying ZTCAP Policy
- SHIELD IDUser Authentication Based on Foundation
- External Exposure and Access Control of Internal Work Systems
Relay Proxy Service (In/Outbound)
Inbound
- Securely relay when accessing internal systems from outside
- Safely exposing internal work systems to the outside
- **RBI(Remote Browser Isolation)**Support for external access screen isolation based on
Outbound
- A structure that allows external access only through URLs registered on the internal network.
- URL Access Control and Policy Management
- Internal IP Protection and Masking
Other Features
- Console UIManagement of underlying network/IP/DNS/firewall settings
- operating only with a browser without separate installationAgentless Environment
- Web-based access to internal network assets (PCs, servers, etc.)**Remote Desktop (RDP)andConsole Access (SSH)**support
Deployment Type
- Provided as an integrated VM image (OVF)
- Selective activation of Inbound / Outbound server after single installation is possible.
- Configuration Management through Console UI (DNS, Firewall, URL Registration, IP Mapping, etc.)