Chapter 4
4 - 24
Configuring global SSL VPN settings
First, configure the global SSL VPN settings that apply to all groups, and
then configure the SSL VPN Webifyer settings for each group.
To configure the global SSL VPN settings
1. Under the Server tab on the left side of the Administrative Console,
click the Security link.
2. Click the SSL VPN link.
3. In the Network Address and Mask boxes, enter the network
address and network mask for the subnet you want VPN users to
use.
In other words, a user who uses VPN to access the server is assigned
an IP address in this subnet. Note that it is a network and not a
single host IP address. (The address ends with .0.)
4. Do one of the following:
• To use NAPT to access the LAN, enable the Use NAPT to
Access LAN option.
• To use a virtual subnet, disable the Use NAPT to Access LAN
option.
Here is a comparison of the two methods of using the Use NAPT to
Access LAN option to configure a VPN back end.
For example, use NAPT when you only need to provide Outlook
users with complete Exchange access. VPN configuration is
completely limited to the FirePass server.
The use of a virtual network ensures complete transparency. A
disadvantage is that the surrounding infrastructure has to be
configured to route IP traffic to the virtual network IP addresses.
Note: The pool of addresses is used in both cases to issue addresses
to the remote endpoints.
Virtual Subnet
NAPT
Does not require infrastructure changes on
the network
No
Yes
IP Addresses used
Pool of virtual
subnet IPs
Single FirePass
IP address
Supports Microsoft Networking
Yes
No
Works with most client server applications
Yes
Yes
Works with more demanding networking
applications
Yes
No
Summary of Contents for FirePass
Page 1: ...FirePassTM Server Administrator Guide version 4 0 MAN 0081 00 ...
Page 2: ......
Page 4: ...ii ...
Page 5: ...Table of Contents ...
Page 6: ......
Page 12: ......
Page 18: ...Chapter 1 1 6 ...
Page 20: ......
Page 44: ...Chapter 2 2 24 ...
Page 46: ......
Page 82: ...Chapter 3 3 36 ...
Page 84: ......
Page 124: ......
Page 156: ...Chapter 5 5 32 ...
Page 158: ......
Page 168: ......
Page 177: ...Index ...
Page 178: ......