To configure IF-MAP client settings on the Infranet Controllers or SA appliances that will
be IF-MAP clients:
1.
In the NSM navigation tree, select
Device Manager
>
Devices
. Click the
Device Tree
tab, and then double-click the Secure Access device for which you want to configure
IF-MAP client settings.
2.
Click the
Configuration
tab. In the configuration tree, select
System > IF–MAP
Federation > Overview
.
3.
From the IF-MAP Configuration list, select
IF-MAP Client
.
4.
Type the server URL for the IF-MAP Web service on the IF-MAP server. For a Juniper
IF-MAP server, use:
https://<FQDN>/dana-ws/soap/ifmap
FQDN is the fully qualified domain name of the replica's internal or external interface;
for a cluster, the FQDN of the internal or external VIP should be used.
5.
Under Authentication Type, select the Client Authentication Method:
Basic
or
Certificate
.
•
If you select
Basic
, enter a username and password. The same information should
be added to the IF-MAP server.
•
If you select
Certificate
, choose which Certificate Authority (CA) to use to verify
the certificate for this client. Optionally, specify certificate attributes or restrictions
to require values for certain client certificate attributes.
•
Ensure that the certificate of the CA that signed the IF-MAP server certificate is
added from the System > Configuration > Certificates > Trusted Server CAs page.
The IF-MAP client validates the IF-MAP server certificate: if validation fails, the
connection fails. Ensure that the hostname in the IF-MAP URL on the client machine
matches the hostname of the server certificate on the IF-MAP server, and that the
CA that signed the server certificate is configured as a trusted server CA on the
IF-MAP client.
6.
Click
OK
to save the changes.
Related
Documentation
Configuring IF-MAP Session Export Policy on the Secure Access Device (NSM Procedure)
on page 285
•
•
Configuring IF-MAP Servers (NSM Procedure) on page 283
Configuring IF-MAP Session Export Policy on the Secure Access Device (NSM
Procedure)
Session-export policies determine how users are identified on the IF-MAP server when
their session is published through IF-MAP. The session-export policy sets the IF-MAP
identity.
285
Copyright © 2010, Juniper Networks, Inc.
Chapter 20: Configuring IF-MAP Federation Settings
Summary of Contents for NETWORK AND SECURITY MANAGER
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 12: ...Copyright 2010 Juniper Networks Inc xii Configuring Secure Access Devices Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii Configuring Secure Access Devices Guide...
Page 20: ...Copyright 2010 Juniper Networks Inc 2 Configuring Secure Access Devices Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 10 Configuring Secure Access Devices Guide...
Page 40: ...Copyright 2010 Juniper Networks Inc 22 Configuring Secure Access Devices Guide...
Page 46: ...Copyright 2010 Juniper Networks Inc 28 Configuring Secure Access Devices Guide...
Page 50: ...Copyright 2010 Juniper Networks Inc 32 Configuring Secure Access Devices Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 34 Configuring Secure Access Devices Guide...
Page 82: ...Copyright 2010 Juniper Networks Inc 64 Configuring Secure Access Devices Guide...
Page 110: ...Copyright 2010 Juniper Networks Inc 92 Configuring Secure Access Devices Guide...
Page 154: ...Copyright 2010 Juniper Networks Inc 136 Configuring Secure Access Devices Guide...
Page 224: ...Copyright 2010 Juniper Networks Inc 206 Configuring Secure Access Devices Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 216 Configuring Secure Access Devices Guide...
Page 288: ...Copyright 2010 Juniper Networks Inc 270 Configuring Secure Access Devices Guide...
Page 300: ...Copyright 2010 Juniper Networks Inc 282 Configuring Secure Access Devices Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 292 Configuring Secure Access Devices Guide...
Page 312: ...Copyright 2010 Juniper Networks Inc 294 Configuring Secure Access Devices Guide...
Page 320: ...Copyright 2010 Juniper Networks Inc 302 Configuring Secure Access Devices Guide...
Page 322: ...Copyright 2010 Juniper Networks Inc 304 Configuring Secure Access Devices Guide...
Page 337: ...PART 6 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 338: ...Copyright 2010 Juniper Networks Inc 320 Configuring Secure Access Devices Guide...
Page 340: ...Copyright 2010 Juniper Networks Inc 322 Configuring Secure Access Devices Guide...