413
Enabling remote access with clientless VPN
Defining VPN profiles to allow communication between the security gateway and clientless users
4
Optionally, do one of the following:
■
To save your configuration and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
■
■
“Using the security gateway as a mail proxy”
Defining VPN profiles to allow communication between the
security gateway and clientless users
A VPN profile specifies a range of assignable IP addresses that are used by the clientless VPN users
when they log on to clientless VPN.
A VPN profile contains the network definitions that are automatically downloaded to the remote user’s
system when they authenticate and access clientless VPN. Secure Network Connection (SNC) allows bi-
directional communication between internal systems and the remote user system.
SNC resembles IPsec VPN in that communication is routed over the secure channel based on the
destination network. SNC is the most flexible mode from an application perspective since it is
application agnostic. SNC is only supported on Microsoft Windows XP/ Microsoft Windows 2000 client
systems.
SNC can use an external DHCP server or a range of IP addresses to assign addresses. If an address pool
is used, when a user connects, the gateway automatically assigns and downloads an IP address from
the address pool to the client system. The security gateway also downloads internal routes and DNS
information. Finally, the security gateway proxy uses address resolution protocol to resolve the IP
addresses assigned to the clients, enabling bi-directional communication.
Prerequisites
Complete the following tasks before beginning this procedure:
■
“Configuring users for internal authentication”
■
“Configuring user groups for internal and external authentication”
To create a VPN Profile
1
In the SGMI, in the left pane, under Policy, click
Clientless VPN.
2
In the right pane, on the Clientless VPN Profiles tab, click
New
.
3
In the VPN Profile Properties dialog box, on the General tab, do the following:
Profile name
Type a name for the VPN profile. Do not use spaces.
IDS/IPS policy
Optionally, in the drop-down list, select an intrusion detection/intrusion prevention
policy to apply to traffic.
Apply firewall rules
Optionally, check to enable full application inspection of VPN traffic.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...