450
Enabling remote access with clientless VPN
Ensuring client compliance for clientless VPN users
3
Optionally, do one of the following:
■
To save your configuration and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
4
After configuring client compliance, you can apply it to the following:
■
Clientless VPN roles
■
User groups
Related information
For further information related to this topic, see the following:
■
■
“Applying client compliance to clientless VPN roles”
■
“Applying client compliance to user groups”
Applying client compliance to clientless VPN roles
You can control the action taken against non-compliant clients based on individual users or user
groups. Three possible actions can be taken:
In the Warn and Deny cases, a message is displayed explaining in what way the client is non-compliant,
based on the selections made in the Client Compliance window.
Prerequisites
Complete the following tasks before beginning this procedure:
■
“Ensuring client compliance for clientless VPN users”
To apply client compliance
1
In the SGMI, in the left pane, under Policy, click
Clientless VPN
.
2
In the right pane, on the Roles tab, select the user role or group role on which you want to enforce
client compliance, and then click
Properties
.
Secondary antivirus
server
Specify the secondary antivirus server by selecting it from the drop-down list.
User name
Type the user name for antivirus server access, if required.
Password
Type the password for antivirus server access, if required.
Allow access to
antivirus and/or
LiveUpdate servers
when non-compliant
Check this option to allow antivirus server and LiveUpdate server access to non-
compliant clients. This option is checked by default.
Note:
This option also allows clients to access antivirus servers via DNS and WINS
ports.
LiveUpdate server
Specify the LiveUpdate server by selecting it from the drop-down list.
Warn
Inform the client of the non-compliance, but allow access anyway.
Deny
Deny access. If the Allow access to antivirus and/or LiveUpdate servers on non-
compliance option is enabled, access is denied to any except antivirus and
LiveUpdate servers.
Ignore
Bypass compliance requirements.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...