Table 38: Configuring Network Connect Connection Profile Details
(continued)
Your Action
Options
Specify the encryption method by choosing one of the following:
•
AES128/MD5 (maximize performance)
—This option instructs the device to
employ Advanced Encryption Standard (AES) 128-bit encryption on the data
channel and the MD5 authentication method for Network Connect sessions.
•
AES128/SHA1
—This option instructs the device to employ AES 128-bit encryption
on the data channel and the SHA1 authentication method during Network Connect
sessions.
•
AES256/MD5
—This option instructs the device to employ AES 256-bit encryption
on the data channel and the MD5 authentication method for Network Connect
sessions.
•
AES256/SHA1 (maximize security)
—This option instructs the device to employ
AES 256-bit encryption on the data channel and the SHA1 authentication method
during Network Connect sessions.
Encryption
Select
No Compression
from the drop-down list if you do not want to employ
compression for the secure connection.
Compression
Select
Selected
from the drop-down list if you want to select roles for the connection
profile. Upon selection, the Role Selections tab is enabled.
Applies to roles
IP Allocation tab
Specify the method of client-side IP address assignment. Select one of the following
options from the drop-down list:
•
DHCP server
—This option allows you to specify the hostname or IP address of
a network Dynamic Host Configuration Protocol (DHCP) server responsible for
handling client-side IP address assignment.
By default, the client’s hostname is sent by the device to the DHCP server in the
DHCP hostname option (option12.) Passing the user ID in the DHCP hostname
option is no longer supported. As an alternative, you can configure the following
entry in the DHCP options table:
option number=12
,
option value=<username><authmethod>
,
option type=String
.
Or you can pass a value by adding an entry in the DHCP options table for hostname
with whatever value you want. For example:
option number=12
,
option value=foo
,
option type=String
.
NOTE: The Secure Access device does not send a DHCP release to the DHCP server
after the Network Connect session terminates.
•
IP Pool
—This option allows you to specify IP addresses or a range of IP addresses
for the device to assign to clients that run the Network Connect service. Use the
canonical format:
ip_range
.
IP address pool also supports attribute substitution. For example, you can enter
a RADIUS role-mapping attribute in this field, such as
<userAttr.Framed-IP-Address>
.
IP Address Assignment
DNS tab
Select this option to enable the DNS setting options. Upon selecting this option, the
DNS settings box gets enabled.
Custom DNS settings
157
Copyright © 2010, Juniper Networks, Inc.
Chapter 10: Configuring Secure Access Resource Policies
Summary of Contents for NETWORK AND SECURITY MANAGER
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 12: ...Copyright 2010 Juniper Networks Inc xii Configuring Secure Access Devices Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii Configuring Secure Access Devices Guide...
Page 20: ...Copyright 2010 Juniper Networks Inc 2 Configuring Secure Access Devices Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 10 Configuring Secure Access Devices Guide...
Page 40: ...Copyright 2010 Juniper Networks Inc 22 Configuring Secure Access Devices Guide...
Page 46: ...Copyright 2010 Juniper Networks Inc 28 Configuring Secure Access Devices Guide...
Page 50: ...Copyright 2010 Juniper Networks Inc 32 Configuring Secure Access Devices Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 34 Configuring Secure Access Devices Guide...
Page 82: ...Copyright 2010 Juniper Networks Inc 64 Configuring Secure Access Devices Guide...
Page 110: ...Copyright 2010 Juniper Networks Inc 92 Configuring Secure Access Devices Guide...
Page 154: ...Copyright 2010 Juniper Networks Inc 136 Configuring Secure Access Devices Guide...
Page 224: ...Copyright 2010 Juniper Networks Inc 206 Configuring Secure Access Devices Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 216 Configuring Secure Access Devices Guide...
Page 288: ...Copyright 2010 Juniper Networks Inc 270 Configuring Secure Access Devices Guide...
Page 300: ...Copyright 2010 Juniper Networks Inc 282 Configuring Secure Access Devices Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 292 Configuring Secure Access Devices Guide...
Page 312: ...Copyright 2010 Juniper Networks Inc 294 Configuring Secure Access Devices Guide...
Page 320: ...Copyright 2010 Juniper Networks Inc 302 Configuring Secure Access Devices Guide...
Page 322: ...Copyright 2010 Juniper Networks Inc 304 Configuring Secure Access Devices Guide...
Page 337: ...PART 6 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 338: ...Copyright 2010 Juniper Networks Inc 320 Configuring Secure Access Devices Guide...
Page 340: ...Copyright 2010 Juniper Networks Inc 322 Configuring Secure Access Devices Guide...