Support

General FAQ

Features

What is the iNetSec Inspection Center®?

iNetSec Inspection Center® is PFU System’s affordable Network Access Control (NAC) solution.

Inspection Center is based on proven PFU technology, already trusted by 200+ companies, including Fortune Global 500 customers, to keep their networks safe. Launched in 2004, and updated annually, iNetSec is the #1 NAC solution in Japan and has been deployed across more than 420,000+ endpoints.

What are the benefits of iNetSec®?

iNetSec keeps networks secure from external threats and internal breaches, such as viruses and P2P software, by enforcing security measures on desktops and laptops.

iNetSec is easy to deploy virtually, making it highly reliable, highly scalable and simple to implement without the need to change existing network designs or purchase new hardware.

iNetSec is easy to maintain, as the solution features automated security policy setting, making it free of human error and requiring minimal administrative resources or costs.

What is the virtual appliance?

The virtual appliance is a software image file that includes an OS and necessary modules. You don't need to install any complex configurations, simply allocate the image on a server, install the sensor software and assign the settings.

Does iNetSec require any special network devices?

No. iNetSec doesn't require special network devices.

What is sensor software?

Sensor software detects newly connected computers and blocks them from network access. Once security posture testing is complete and a computer complies with security policy, the software sensor then allows the complaint computer to connect.

Does iNetSec have the ability to perform registry scans?

Yes. iNetSec can perform registry checks for required software such as corporate asset tags, and it can also scan any file – including configuration files, log files and executable files – for prohibited software.

Does iNetSec offers a Grace Period?

Yes. iNetSec allows for a Grace Period so IT administrators can set the length of time in which non-compliant computers can be connected to the network. iNetSec delivers the non-compliant end users with a warning, offering steps needed to comply with policy in order to remain connected. Once the Grace Period is exceeded, the non-compliant computer will be disconnected.

Does iNetSec support Active Directory for user authentication?

Yes. iNetSec supports Active Directory, LDAP and RADIUS for user authentication through RADIUS protocol.

Installation

Can I get a trial version to evaluate this product?

Yes. Qualified companies can register for a free initial trial period. Please visit the PFU Web site for more details.

How many client PCs can iNetSec operate?

PFU supports up to 3,000 client PCs per one iNetSec server. If you’re interested in learning how our solution can accommodate more clients with additional iNetSec servers, please contact us.

What would happen if an iNetSec server exceeded 3000 clients? Would the server shutdown or will the performance level be affected? What sort of warnings does iNetSec provide in situations such as these?

iNetSec can accommodate additional clients but performance may be affected if more than 3000, clients connect to the network.

How can iNetSec be deployed in my network environment?

Simply allocate the image on a server, install the sensor software and configure the simple settings. As common practice, iNetSec Inspection Center® can be deployed at the server farm at your organization. The sensors can be deployed throughout locally or remotely.

Do I need to install any agent software on each client PC?

No. iNetSec provides the agent software as an Active-X. When client PCs are directed to the inspection server the first time they will be required to install the Active-X software (dissolvable agent) for Windows OS or Java for Mac OS. Persistent agent software can also be provided as an alternative to the Active-X agent for Windows OS.

Can iNetSec handle HA? Are there additional costs?

There is no extra cost for an administrator to install iNetSec on two servers if one is for HA purposes.

The IT administrator will also be able to configure the VMware environment for HA.

Does iNetSec require extra steps for end users to login?

No, iNetSec provides a non-intrusive scan mechanism and it will not require additional steps for domain users.

Can iNetSec work in wireless network environments?

Yes, iNetSec can control PCs that connect to a wireless access point and we have several different scenarios for wireless deployment, so please contact PFU for more details.

Can iNetSec work in a VLAN environment?

Yes. A sensor PC (a PC where the sensor software has been installed) can control a single VLAN so a sensor PC is required for each VLAN.

Should I include the proxy server as a protected or non-protected resource?

If you would like to provide internet access for remediation, the proxy server should be included in the non-protected resource since the proxy server address is specified in all IP packets for http proxy. If you would like to restrict access to the Internet, you should include the proxy server in the protected resource.

I do not have a proxy server. How can I provide access to the Internet before PC health check?

You can specify IP addresses of servers located outside of the corporate network as non-protected network resources.

Can I deploy iNetSec behind my VPN?

PFU will be deploying VPN support soon. Please contact us for more details.

Can I use a wireless network to connect a sensor PC?

No. A wireless network doesn’t have stable radio waves and the poor signal quality may cause delays in detecting non-compliant PCs. PFU strongly recommends using a wired network for the connection of a sensor PC.

Operations

Do I need to update the Microsoft security patch information and pattern numbers for anti-virus software daily?

No. PFU delivers this information as soon as Microsoft issues the patches or pattern files are updated by anti-virus vendors. An administrator can configure their dictionary download settings so that iNetSec downloads the dictionary and imports it automatically. Please note that such information will be delivered in accordance with the maintenance contract.

How can security policies be managed with iNetSec?

iNetSec provides a web-based interface to manage policies. Simply access the iNetSec server URL and log-in to the Management Console.

Is iNetSec itself secure?

Yes. iNetSec is created as a virtual appliance and all ports, except those used by iNetSec, are blocked. iNetSec can not be accessed directly via remote shell, telnet, ftp, etc. Additionally, the number of PCs that can access the Management Console can be limited with IP address ranges.

Can I import and export my configurations for iNetSec?

Yes. iNetSec provides functions to import and export configurations through the Management Console.
Even if the disk image is damaged, iNetSec configurations can be easily recovered.

Supported Environment

What operating systems does iNetSec support?

For the latest supported operating systems, please contact PFU.
Current supported operating systems include:

Supported OS  
Management Console Windows® XP SP3 (32/64 bit), Windows Vista® SP2 (32/64 bit),  Windows® 7 (32/64 bit)
Windows Web Client / Windows Install Client Windows XP SP2/SP3, Windows Vista (32/64 bit), Windows 7 (32/64 bit)
Mac Web Client Mac OS X 10.4, 10.5, 10.6 and 10.7 (Intel Platform only)
Sensor PC Windows XP SP3, Windows Vista SP2 (32 bit), Windows 7 (32 bit)
What versions of VMware does iNetSec support?

For the latest supported VMware products, please contact PFU.

Current supported VMware products include:

  • VMware® vSphere™ 4.0, 4.1 and 5.0
  • VMware® vSphere Hypervisor™ (based on ESXi 4.1 and 5.0)
  • VMware® ESXi 4.0 and 4.1

Maintenance

If the iNetSec server has any issues, can employees continue to use the network?

Yes, if the iNetSec settings are configured accordingly. Each sensor can be set as block or open. If set to open, the,sensor software will not block PCs and employees can continue to use network.

If there are issues with sensor software, can iNetSec continue to detect the sensor PC?

Yes. As iNetSec continues to communicate with sensors periodically, iNetSec can detect which sensors might have problems, and will automatically send out an email notification.

Who maintains the OS in the virtual appliance such as when applying security patches?

PFU maintains the OS. Security patches for the OS will be provided for the virtual appliance