Secure Mobile Access 12.4 Deployment Guide

Tunnel, Proxy, or Web: Which Access Method is Best?

The SMA access services and clients offer a wide array of methods with different degrees of capability for reaching your organization’s resources. Use the table below to determine which ones are best for you and your users.

Other factors to consider, aside from technical requirements, are:

  • Security requirements such as the safeguards you want to put in place on the desktop.

  • User profiles, including the levels of technical sophistication among your users.

  • Administrative resources available to manage and support a VPN.

The below table summarizes the access methods and their advantages.

Access Method Provides Access to Advantages

Connect Tunnel

Full network access to client/server applications, Web resources, network shares, and bi-directional applications such as VoIP, SMS, and FTP.
  • Stand-alone client installed from WorkPlace portal or from custom installer package, with no rebooting required.

  • Enhanced security options including split tunneling, and redirection of all traffic or only local traffic.

  • Local printing support.

  • Typically used for remote access on systems that can be readily managed by IT such as a corporate laptop used by a traveling or remote employee.

    Administrator rights are required for installation.

OnDemand Tunnel Full network access to client/server applications, Web resources, network shares, and bi-directional applications such as VoIP, SMS, and FTP.
  • Activated from the WorkPlace portal.

  • Enhanced security options including split tunneling, and redirection of all or only local traffic.

  • Local printing support.

  • Auto-updating (Windows client only).

    Administrator rights are required for installation.

Mobile Connect Client/server applications, thin-client applications, and Web resources. Stand-alone, lightweight application that runs on iOS, Android, Mac OS, Chrome OS, and Windows 10 desktops.
WorkPlace Lite Access mode that bypasses all Access and EPC Agents and logs the user in to WorkPlace.
  • Requires a modern web browser that supports HTML5

  • Users can access any network URL using Intranet field (if allowed by administrator)

ActiveSync Email, calendar, contacts, tasks, and out-of-office functions available from the Exchange server. Convenient email and related functions access from Apple iPhones and iPads, smart phones running the Google Android operating system, and smart phones running the Symbian operating system.
OnDemand proxy agent Thin client/Server applications.
  • Activated from the WorkPlace portal.

  • Provides access to services such as RDP, Citrix, or SSH.

Translated Web access

Custom Port Mapped Web access

Custom FQDN Mapped Web access

Any Web resource (including Web-based applications, Web portals, and Web servers).

Translated Web on Windows operating systems also offers access to network shares.

Custom Port Mapping provides access via a specific port defined by the administrator, which must be open on the external firewall.

Custom FQDN Mapping provides access via DNS and requires new DNS entries and possibly a new SSL certificate and IP address.

Convenient access to Web and file system resources from any Web browser that supports SSL.

No client configuration or administration tasks.

Supports the use of aliases to hide internal host names in the browser address bar.

Single sign-on to back-end Web servers.

A good option for providing business partner access, because it does not require any client configuration or administration.

Custom Port Mapping and Custom FQDN Mapping handle Web programming technologies such as JavaScript without the limitations of URL rewriting used in translation.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden