Ivanti Neurons for Secure Access is a Software-as-a-Service (SaaS) platform that provides centralized management, real-time analytics, and enhanced security for Ivanti Connect Secure (VPN) and Ivanti Neurons for Zero Trust Access (ZTA) gateways. It offers a unified, cloud-based interface to streamline the administration of distributed gateway deployments, reducing complexity, time, and risks associated with managing multi-node VPN and ZTA environments. The platform delivers comprehensive visibility into users, devices, applications, and infrastructure, with features like user risk scoring, unified logging, custom reporting, and one-button gateway upgrades. Hosted on Microsoft Azure, it integrates seamlessly with existing Ivanti deployments without altering user workflows or data sovereignty, making it ideal for organizations modernizing VPN infrastructure while transitioning to Zero Trust security.
- Architecture:
- Components:
- Ivanti Neurons Platform: Cloud-based SaaS platform hosted on Microsoft Azure, providing management and analytics services.
- Management Console: Web-based interface for gateway configuration, user tracking, and reporting.
- Secure Access Client: Optional client software (used with Connect Secure/ZTA) for end-user connectivity.
- APIs: REST APIs for integration with IDP, SIEM, UEM, and vulnerability assessment tools.
- Deployment Options:
- Cloud-Native: Fully managed SaaS on Azure, no on-premises infrastructure required.
- Hybrid: Manages on-premises or cloud-based Connect Secure/ZTA gateways from the cloud console.
- Scalability: Supports thousands of gateways and millions of users/devices; scales with Azure infrastructure.
- Operation Mode: Agentless management for gateways; integrates with Secure Access Client for end-user devices.
- Components:
- Supported Gateways:
- Ivanti Connect Secure: Physical/virtual appliances (PSA series, vADC) for SSL VPN.
- Ivanti Neurons for ZTA: Cloud-based ZTA gateways for Zero Trust access.
- Third-Party VPNs: Limited co-existence with non-Ivanti VPNs via API integrations.
- Supported Platforms:
- Admin Console: Accessible via Chrome, Edge, Firefox, Safari (latest versions).
- Managed Devices: Windows 10/11, macOS 11–14, iOS 11+, Android 8+, Linux (limited).
- Infrastructure: On-premises (VMware ESXi, Hyper-V), cloud (AWS, Azure, Google Cloud), or edge deployments.
- Management Features:
- Gateway Lifecycle: Centralized upgrades, downgrades, restarts, and retirement.
- Configuration Groups: Templates for consistent multi-node gateway configuration.
- One-Button Upgrades: Simplifies patching and firmware updates across gateways.
- Hybrid Support: Manages gateways in cloud, on-premises, or edge environments.
- Authentication:
- Integration: Azure AD, Okta, Ping Identity, Active Directory, SAML 2.0 for SSO.
- MFA: Ivanti Neurons MFA, Duo, Google Authenticator, RSA SecurID.
- Access Control: Role-based access for admins; granular policies for gateway access.
- Security and Analytics:
- User Risk Scoring: Detects risky behavior (e.g., multiple logins from different locations) using UEBA.
- Unified Logging: Collates logs from all gateways for centralized analysis.
- Custom Reporting: Scheduled or on-demand reports with charts and graphs.
- Automated Remediation: Triggers actions (e.g., quarantine, step-up authentication) based on risk scores.
- Compliance: Supports GDPR, HIPAA, PCI-DSS, ISO 27001.
- Integrations:
- Ivanti Ecosystem: Ivanti Connect Secure, Neurons for ZTA, Neurons for UEM, Policy Secure (NAC), Neurons for ITSM.
- Third-Party: ServiceNow, Splunk, Palo Alto Networks, Microsoft Intune, MobileIron, Okta, SIEM platforms.
- APIs: Clean REST APIs for IDP, SIEM, UEM, vulnerability assessment, and endpoint protection.
- Visibility and Reporting:
- Dashboards: Single-pane view of gateways, users, devices, and activities.
- Reports: Customizable for user behavior, gateway health, compliance, and app usage.
- Filters: Advanced filtering for log analysis, savable for future use.
- Service Maps: Visualizes gateway-to-application dependencies.