Users can access VPN resources secured by the SMA appliance using three primary methods, or access services. This section describes each of the access services and the types of resources they provide access to.
The network tunnel service is a network routing technology that provides secure network tunnel access to a wide range of client/server applications, including those that use non-TCP protocols such as VoIP and ICMP, reverse-connection protocols, and bi-directional protocols, such as those used by remote Help Desk applications. It works in conjunction with the Connect Tunnel client and the OnDemand Tunnel agent to provide authenticated and encrypted access. The network tunnel service can traverse firewalls, NAT devices, and other proxy servers that can interfere with traditional VPN devices.
When Web resource filtering is enabled for the network tunnel service, policies for tunnel sessions can use URL-based rules in addition to IP-based rules.
The below table illustrates the relationships between the Secure Mobile Access access services and the user access components that they control.
| Service | User access components | Description |
| Network tunnel service |
|
|
| Web proxy service |
|
|
| WorkPlace service |
|
|