Configuring the FirePass Webifyers
FirePass
™
Server Administrator Guide
4 - 23
Configuring SSL-VPN
The FirePass server’s SSL VPN provides the functionality of a traditional
IPSec VPN client, but it is easier to deploy. Unlike a traditional IPSec VPN
client, the SSL VPN Webifyer does not require any configuration on each
remote user’s computer, and no server-side changes are necessary. The
FirePass server’s SSL VPN implements PPP over SSL, which is a secure
solution that does not have problems with routers, firewalls, or proxies.
Whereas the AppTunnels Webifyer provides remote users with access to
particular applications on a specific server and port, the SSL VPN Webifyer
provides access to all applications and network resources, unless you
configure restrictions.
As with the AppTunnels Webifyer, the SSL VPN Webifyer uses the
standard HTTPS protocol, works through all HTTP proxies, and leverages
all of the setup, security, availability, and management features of the
FirePass server.
The SSL VPN Webifyer provides these benefits:
◆
Browser-based access to client-server applications.
The self-configuring SSL VPN Webifyer does not require any
pre-installed, pre-configured software on the remote system. Field staff
and travelers can access their applications without needing any individual
setup or configuration of their computers. The SSL VPN Webifyer
supports UDP and TCP applications.
◆
Simple maintenance.
Upgrades or replacement of field computers do not require any additional
VPN-related maintenance, and changes to the host network or IP address
can be made without reconfiguring each remote user’s computers.
◆
Split tunneling.
If this option is enabled, only traffic intended for the target LAN goes
through the SSL VPN Webifyer. All of the user’s other Internet activity
is unchanged, and is handled by the ISP as though the SSL VPN
Webifyer was not deployed.
◆
Packet-based, group-based firewall.
Groups of users can be restricted to particular ports and addresses within
the LAN. This feature allows full client-server application support
without opening the entire network up to each user.
In addition, the FirePass server’s SSL VPN has global and group-based
packet filters, so that you can define groups of users with different access
rights.
Note
The first time users access the AppTunnels Webifyer, an ActiveX control is
automatically installed in their Internet Explorer browser, or a plug-in is
automatically installed in their Netscape or Mozilla browsers on Windows.
Summary of Contents for FirePass
Page 1: ...FirePassTM Server Administrator Guide version 4 0 MAN 0081 00 ...
Page 2: ......
Page 4: ...ii ...
Page 5: ...Table of Contents ...
Page 6: ......
Page 12: ......
Page 18: ...Chapter 1 1 6 ...
Page 20: ......
Page 44: ...Chapter 2 2 24 ...
Page 46: ......
Page 82: ...Chapter 3 3 36 ...
Page 84: ......
Page 124: ......
Page 156: ...Chapter 5 5 32 ...
Page 158: ......
Page 168: ......
Page 177: ...Index ...
Page 178: ......