White Paper XenMobile and Palo Alto Networks End-to-End Application Security for Mobility Environments. citrix.com White Paper XenMobile and Palo Alto Networks Today’s mobile business environments require the highest levels of end-point security. Mobile devices and applications are vulnerable to outside threats, and pose a threat to valuable corporate data. A combined solution between Citrix and Palo Alto Networks delivers a comprehensive security solution for mobile environments that combines scalable multi-layer data inspection with the ability to dynamically identify and take action against network threats. Citrix and Palo Alto Networks have tested and validated a solution for mobile security using Citrix NetScaler Application Delivery Controller and the Palo Alto Networks next-gen firewall in the DMZ. This complimentary solution also includes Citrix XenMobile Enterprise Mobile Management server running behind the next-generation firewall. Architecting this solution is simple with next-hop configuration. Figure 1: Complete Application Security for Mobile Environments NetScaler’s secure highly scalable VPN capabilities combined with Palo Alto Networks nextgeneration firewall abilities to inspect traffic at the application layer and enforce security policy provides a best-of-breed high performance intelligent architecture for delivering scalable security services to the mobile end-point. citrix.com 2 White Paper XenMobile and Palo Alto Networks Citrix XenMobile Enterprise Mobility Management (EMM) solutions enhance the NetScaler and Palo Alto Networks infrastructure components by managing and delivering device and application security. XenMobile delivers a common set of Mobile Device Management (MDM) and Mobile Application Management (MAM) policies and that can be applied to all users, device types and applications. The diagram below depicts how a customized set of mobile security polices can be provisioned using XenMobile EMM. On the left is a set of triggers, on the right a set of actions. The compliance engine works with different combinations triggers and actions to provide customized mobile end-point management. Figure 2: Automated Device Compliance The deployment of Citrix NetScaler and the Palo Alto Networks next-generation firewall delivers security for mobile environments with intelligent application level visibility and control. Palo Alto Networks next-generation firewall provides application level visibility that can filter traffic on end-point context such as user and content. Many legacy firewalls take a simple “allow or deny” approach. Palo Alto Networks next-generation firewall provide the granularity to take more precise action based on who the user is and the applications that they use. • Enforce security policies based on applications, users and content for next-generation control over traffic. • Provide an extra layer of security to applications by adding content filtering capabilities for XenMobile Worx Apps like WorxMail and WorxWeb. Organizations can establish security policies to stop known and unknown threats, enforce URL filtering, and block data. citrix.com 3 White Paper XenMobile and Palo Alto Networks • Leverage intelligent traffic management capabilities by prioritizing IP data flows (Diff Serv) into 8 separate queues to guarantee application performance in the data center as well as on the upstream and downstream networking devices. • Apply traffic shaping for bandwidth intensive applications, such as media streaming, with webusage controls. An intelligent secure mobile environment requires secure devices and apps but also requires the ability to intelligently monitor and control application data and data flows. Citrix NetScaler and Palo Alto Networks next-generation firewall provide deep packet inspection with the ability to visualize, monitor and control data at the application level. Palo Alto Networks and Citrix NetScaler provide best-of-breed application security across the wire while Citrix XenMobile provides best-of-breed application security on the mobile device. Together this validated solution provides enterprise IT with all the key components required to architect next-generation mobile environments. citrix.com 4 White Paper enMobile and Palo Alto Networks Corporate Headquarters Fort Lauderdale, FL, USA India Development Center Bangalore, India Latin America Headquarters Coral Gables, FL, USA Silicon Valley Headquarters Santa Clara, CA, USA Online Division Headquarters Santa Barbara, CA, USA UK Development Center Chalfont, United Kingdom EMEA Headquarters Schaffhausen, Switzerland Pacific Headquarters Hong Kong, China About Citrix Citrix (NASDA CT S) is leading the transition to software-defining the workplace, uniting virtualization, mobility management, networking and SaaS solutions to enable new ways for businesses and people to work better. Citrix solutions power business mobility through secure, mobile workspaces that provide people with instant access to apps, desktops, data and communications on any device, over any network and cloud. ith annual revenue in of . billion, Citrix solutions are in use at more than , organizations and by over million users globally. Learn more at www.citrix.com Copyright Citrix Systems, Inc. All rights reserved. Citrix, enMobile, Citrix Receiver, enDesktop, enApp, Share ile and NetScaler are trademarks of Citrix Systems, Inc. and or one of its subsidiaries, and may be registered in the U.S. and other countries. ther product and company names mentioned herein may be trademarks of their respective companies. 0216/PDF citrix.com 5