Enabling Secure and Optimized Access for Remote Workers with VMware Secure Access

With VMware Secure Access, VMware has combined the consistent, secure cloud application access functionality of VMware SD-WAN with the capability of Workspace ONE to allow only trusted devices and users to access applications hosted on-premises or in the cloud. 

This guide will walk you through demonstrating VMware Secure Access for Workspace ONE in the ready to use TestDrive environment.

Contents

Before You Begin

In order to complete a VMware Secure Access Walkthrough, you'll need the following:

  • A valid VMware TestDrive account.
  • Enabled Workspace ONE UEM service in the VMware TestDrive portal.
  • A recommended device: Recent, updated Windows 10 physical or VM.  Windows 10 Enterprise evaluation ISO is available via Microsoft download. Maintain a clean VM snapshot, or System Restore point on a physical device, for a fast roll back.

    Tip!

    To keep your VM in tip-top shape, first build a new completely updated Windows VM, then create a snapshot.  At intervals, revert to the snapshot, update it, then create a new snapshot. 
  • You can also use an iOS, Android, or macOS device.  If using one of those, enrollment and Workspace ONE experience is the same.  Windows is covered herein. 
  • Access to the ready to use Workspace ONE UEM Console.
    • Workspace ONE UEM administrator role: Device Administrator at World Wide Enterprises 
    • For the console-side discussion, be sure you have the UEM console open with the necessary console views already loaded in your browser's tabs.
  • Network access from your device and TCP 443 enabled on your local network.

Introduction

VMware Secure Access enables secure, optimized, and high-performance access for remote and mobile workers.

The VMware Secure Access solution is designed to address enterprise concerns over inconsistent access, poor user experience, and stress on enterprise infrastructure. It will provide a multi-region, per-app VPN service for iOS, Android, Windows and MacOS clients, with role-specific policies allowing for persona-based controls.

VMware Secure Access is delivered as a service through a global network of VMware SASE points of presence (PoPs).

Enrollment

Hub initiated enrollment is currently the recommended Windows enrollment method for a Windows device with a user profile. 

  • Go to https://getwsone.com. Download the Workspace ONE Intelligent Hub (Hub) and install it.
  • When prompted, enter your Workspace ONE enrollment email address to be automatically routed to testdrive.awmdm.com, choose the enrollment OG, and authenticate into Workspace ONE.
     
    Enrollment email:              <username>@vmtestdrive.com                

    Organization Group:   Enterprise - Corporate Owned Demo

    Workspace ONE credentials:    TestDrive username
    TestDrive password
  • Proceed through accepting all prompts until enrollment is completed.

    The Enterprise - Corporate Owned Demo flow (corp) supports modern Windows management including the functionality showcase for VMware Secure Access integrated with Workspace ONE.  Alternatively, the Enterprise - BYOD Demo flow (BYOD) is also set up for VMware Secure Access. However, the BYOD flow is sensitive to a user's privacy where restrictions of any type would be considered intrusive on a personal device, therefore BYOD contains minimal management.  

Check your device in the Workspace ONE UEM console to verify that enrollment has completed.

Workspace ONE UEM Console Overview

Talking Points

  • An enrolled device will receive a set of automatically delivered profiles. Those profiles represent a baseline configuration how the PC should be set up, and additional profiles can be applied to meet specific requirements.
  • Profiles are the settings, when combined with compliance policies, that help enforce organizational security policies.
  • Passcode, Wi-Fi, certificate issuance, app whitelist/blacklist, and device restrictions are just a few profile types that may be created for Windows 10.

Go to Resources > Profiles on the left-side console menu.  On the far right, in the Search List box, enter "WWE - Windows" to quickly filter your view to list only Windows 10 profiles. You can identify the WWE – Windows – WS1 Tunnel profile, which enables Per-App Tunnel access on your enrolled device. 

mceclip12.png

If you wish, click through individual profiles to see review its payload.  Use any pre-configured optional device profiles as needed.

Switch to your browser tab open with the device list. Find your device by filtering by your username. Drill into your device details and discuss profiles, apps, content and other features your audience would find important.

On the profiles tab, note the installed statuses and the assignment types, automatic vs optional, from this view. Again, use optional profiles to aid your discussion.

mceclip13.png

 

Workspace ONE Intelligent Hub

Talking Points

  • VMware Workspace ONE is the enterprise platform that enables organizations to deliver a digital workspace that empowers users to securely bring the technology of their choice—devices and apps—without sacrificing productivity or security at a cost the business needs.
  • The Unified App Catalog transforms employee on-boarding. Simply accessing the Workspace ONE Intelligent Hub app on the PC (or any platform) provides employees with a complete, self-service enterprise app catalog that can be easily customized and branded for your organization.
  • Delivers any application from the latest mobile cloud apps to legacy enterprise apps. Simple, one-stop access to all apps: native, web, virtual desktops (VDI) and applications (RDSH).
    • Internal web apps through a secured browser
    • SaaS apps with SAML-based SSO and provisioning framework
    • Native public mobile apps through brokerage of public app stores
    • Modern Windows apps through the Windows Business Store
    • Legacy Windows apps through Windows app package delivery
  • Single Sign-On (SSO) that federates the most complex on-premises Active Directory topologies and support for multi-factor authentication, like RSA.

After enrollment, Workspace ONE Intelligence Hub automatically launches, preconfigured with the Workspace ONE Access tenant.

With Workspace ONE UEM managed authentication, the user's access into Workspace ONE Intelligent Hub is seamless. Manual user authentication is not required, but can be configured as a fallback method.

mceclip0.png

Proceed into Workspace ONE Intelligent Hub. Discuss the streamlined user access to all assigned apps: native, web, or virtual.

Once inside Workspace ONE Intelligent Hub, review the Categories under Apps showing how the apps are organized and easy to access.

Go over the rapid and seamless access Workspace ONE Intelligent Hub provides for VDI and RDSH under the Virtual Apps category.

Note the Windows Apps seen within the Catalog.  More details on those are coming up.

Automatic Provisioning of Windows Apps

Talking Points

  • No longer do PCs need to be tied to local area network (LAN) computer management systems for native Windows app management. Both Windows 10 desktops and Windows 10 mobile devices can now have Windows apps managed over-the-air (OTA) by Workspace ONE UEM.
  • Workspace ONE UEM provides a variety of different application distribution options to meet the variety of installation scenarios found in an enterprise. The application deployment framework supports MSI, EXE and ZIP based deployments, public apps from the Windows Store, as well as complex script-based applications through product provisioning.
  • Content Delivery Network (CDN) integration globally extends your organization's app deployment for fast and secure app delivery.

Windows's native VMware Horizon Client, Carbon Black Cloud Sensor, Workspace ONE Tunnel, Firefox, and Zoom apps are configured to automatically deploy. These apps are delivered by Workspace ONE UEM's software distribution over CDN. 

Workspace ONE UEM's Windows app distribution and management is doing the same thing that traditional LAN-based tools, like SCCM, have done with native apps, but Workspace ONE UEM is doing it over the air. Devices no longer have to be tied to the organization's LAN.

Several additional Windows Apps are set up for software distribution. Select Windows Apps to filter out all Windows apps, both Windows Desktop and UWP apps:

mceclip1.png

Optionally, choose one of the Windows Apps and push it to your device. 7-Zip is a good one to pick as it’s small deployment.  You’ll receive a notifications on the device regarding the installation.

In Workspace ONE UEM, apps delivered via software delivery are set up through the familiar UEM workflow.  Additionally with Windows Apps, comprehensive deployment, install, dependency, detection, and uninstall settings are configured to suit enterprises' various complex app deployment needs.

Per-app VPN with the Workspace ONE Tunnel

Talking Points

  • Workspace ONE Tunnel enables secure access for all workers and devices working anywhere with an internet connection outside the office.
  • Users never have a 'no-touch' Tunnel experience. Its setup and configuration are 100% managed by Workspace ONE UEM.
  • IT organizations can take a least-privilege approach to enterprise access, ensuring only managed devices, defined apps and domains have access to the internal network.
  • Zero Trust goals can be reached by combining explicit definitions for managed applications and integration with the Workspace ONE compliance engine. 

Workspace ONE UEM will automatically push both the Workspace ONE Tunnel app, the Tunnel app's device profile, and Firefox to your device. Workspace ONE UEM manages Firefox as the per-app Tunnel app.

Workspace ONE UEM also manages the VMware Tunnel's fundamental configurations which establish connectivity and trust within an organization's environment.  Inside this UEM system settings area—elemental to the Workspace ONE Tunnel app's configuration—are the Device Traffic Rules.  

VMware Tunnel configuration/Device Traffic Rules are restricted by Workspace ONE UEM RBAC in testdrive.awmdm.com.

mceclip0.png

Launch Firefox and navigate to the below site using the Hub's Intranet web app.

    http://intranet.vmtestdrive.com/

Next, try to go to the same site using an unmanged browser (Microsoft Edge). Since Edge is not configured as a managed Workspace ONE Tunnel app, Edge has no access to the internal site.

Launch the Workspace ONE Tunnel app to see its configuration which displays its connected state, managed domains (i.e., domains accessible via the Tunnel), and blocked domains.

mceclip0.png

Attempt to load one of the blocked domains. The connection will be refused by the Workspace ONE Tunnel.   

mceclip7.png

Next, load youtube.com and play a HD video.  Then, concurrently on another tab, access techzone.vmware.com and navigate through some of technical articles available (under the Start menu). 

Youtube.com and vmware.com are all public sites; however, they are configured as managed domains in Workspace ONE UEM, therefore the traffic for those websites will be tunneled through the Workspace ONE Tunnel app and VMware Secure Access. 

Next, we'll inspect the network traffic on the WAN.

Securing & Optimizing Network Traffic with VMware SD-WAN Orchestrator

Talking Points

  • VMware SD-WAN is an integral part of the VMWare Secure Access.
  • As traffic integrates into the SD-WAN overlay, Dynamic Multipath Optimization (DMPO) benefits are applied, reducing latency, packet loss, and jitter while improving bandwidth utilization.
  • VMware SD-WAN also provides visibility into the applications accessed by the remote mobile users on their devices.

Go to the VMware SD-WAN Network Orchestrator and click Sign In With Your Identity Provider.

VCO-sign-in.png

You'll be redirected to Workspace ONE Access and, if already logged in, SSO in to the VMware SD-WAN Network Orchestrator.  If not already logged in, just log in with your TestDrive credentials. 

    User name: <TestDrive username>
*** no domain prefix ***
Password: <TestDrive password>

After you successfully authenticate, the orchestrator console will look like below.

mceclip2.png

In Edges, go to testdrive-edge1 > Applications tab.  All of the tunneled applications that are accessed by managed mobile devices are displayed. 

mceclip9.png

Previously, you loaded a Youtube video and browsed websites on your device. You can see all of those applications visibility identified on this tab.

Another important aspect of VMware SD-WAN is the user experience. To enhance user experience, QoS is automatically applied to the traffic, time sensitive traffic like voice and video are automatically identified and classified a high priority. VMware SD-WAN also automatically chooses the best path to the Data Center or SaaS and apply remediation from latency, jitter and packet loss induced from internet to enhance user experience. The enterprise admin can view this by clicking on the “QoE” tab. The tab shows how the application faired with and without VMware SD-WAN.

mceclip10.png

Below is a user experience example showing how VMware SD-WAN improved the video conferencing quality after 2% packet loss was seen without VMware SD-WAN.

image24.gif

Without VMware SD-WAN

                           

image25.gif

With VMware SD-WAN

 

More Info

Have more questions? Submit a request

Article is closed for comments.