
Policies are lists of users and groups that are attached to resources. Users can only access a resource if they are included in the policy attached
to the resource. A resource can include multiple policies that contain separate lists of users and groups. You can grant different users with varying
levels of access to a resource by assigning Access Rights to the user or group. To help you easily assign resources to everybody, a built-in Every
policy is included by default. You can delete the
policy, locking out out all users who do not have a specific Profile, Authentication
one
Everyone
Scheme, or Access Right assigned to them. It is recommended that you create policies for every distinct user group. For example, in a company
with three departments, you can create separate policies for each department, management user, and administrator.
For more information on Policies, see
.
Network Access Control (NAC)
Network access control limits access to network resources, according to a variety of factors that are not connected to the user. Users who fail the
NAC check are not allowed to log in until they have a conforming system. You can define exceptions for single users, so that they can continue
using the service until they have time to update their system. User systems are evaluated by the following parameters:
Time of day
Operating system (type and if it is up-to-date)
IP and MAC address
Browser type and version
Antivirus state (installed/up-to-date)
Firewall
Version of plugins installed
Type of connection (Wi-Fi)
Domain membership
To configure NAC, go to
. To define exceptions, go to
Manage System > ACCESS CONTROL > NAC
Manage System > ACCESS CONTROL >
.
NAC Exceptions
How to Create and Modify User Databases
A user database specifies where user authentication information is stored. The Barracuda SSL VPN 380 and above support multiple user
databases, letting you define different access policies for resources that are shared by users. The Barracuda SSL VPN supports authentication
with the following services:
LDAP
NIS
OpenLDAP
Built-in internal user database