244
McAfee UTM Firewall 4.0.4 Administration Guide
VPN menu features
PPTP VPN Server
6
Select the weakest Authentication Scheme to accept. Access is denied to remote users attempting to
connect using an authentication scheme weaker than the selected scheme. The schemes are described
below, from strongest to weakest.
• Encrypted Authentication (MS-CHAP v2) – The strongest type of authentication to use; this is the
recommended option.
• Encrypted Authentication (MS-CHAP) – This is not a recommended encryption type and should
only be used for older dial-in clients that do not support MS-CHAP v2.
• Weakly Encrypted Authentication (CHAP) – This is the weakest type of encrypted password
authentication to use. It is not recommended that clients connect using this as it provides very little
password protection. Also note that clients connecting using CHAP are unable to encrypt traffic.
• Unencrypted Authentication (PAP) – This is plain text password authentication. When using this
type of authentication, the client password is transmitted unencrypted.
7
Select the Required Encryption Level. Access is denied to remote users attempting to connect not
using this encryption level. Strong Encryption (MPPE 128 Bit) is recommended.
8
Select the user authentication location from the Authentication Database list. This allows you to
indicate where the list of valid clients can be found. You can select from the following options:
• Local – Use the local database defined on the Local Users tab of the Users page. You must enable
the Dial-in Access option for the individual users that are allowed dial-in access.
• RADIUS – Use an external RADIUS server as defined on the RADIUS tab of the Users page.
• – Use an external server as defined on the tab of the Users page.
For further details on users, RADIUS, and TACAS+, refer to
Users menu
.
9
[Optional] To configure Advanced options, click Advanced. The following fields are available:
a
Enter the desired value of the Maximum Transmission appliance (MTU) for the PPTP interfaces into the
PPTP MTU field.
Default: 1400
b
Enter the number of minutes without activity before disconnecting the PPTP client in the Idle Time
(minutes) field.
c
In the DNS Server field, enter the IP address of the DNS server that assigns IP addresses to
connecting PPTP clients.
d
In the WINS Server field, enter the IP address of the WINS server that assigns IP addresses to
connecting PPTP clients.
e
Select the Enable PPTP Debugging checkbox to add PPTP debugging information to server logs.
10
Click Submit.
Adding a PPTP user account
Use this procedure to add a new PPTP VPN user. Keep a note of the User name and Password, as these are
required in configuring the remote PPTP client.
1
Click System > Users > Local Users tab. The Local Users page is displayed.
2
Click New. The Edit User Information page appears.
3
Complete the fields. For further details on adding a user, refer to
Creating a user
. Keep note of the
username and password for when you need to connect to the VPN connection.
4
[Required for VPN PPTP access] Be sure to select the PPTP Access checkbox.
5
If applicable, enter a static IP address in the PPTP Address field.
Summary of Contents for SG310
Page 1: ...McAfee UTM Firewall Administration Guide version 4 0 4...
Page 10: ...10 McAfee UTM Firewall 4 0 4 Administration Guide...
Page 148: ...148 McAfee UTM Firewall 4 0 4 Administration Guide Network Setup menu options SIP...
Page 372: ...372 McAfee UTM Firewall 4 0 4 Administration Guide System menu features Advanced menu...
Page 410: ...410 McAfee UTM Firewall 4 0 4 Administration Guide Index...
Page 411: ......
Page 412: ...700 2237A00...