251
Limiting user access
Configuring user groups for internal and external authentication
7
Optionally, do one of the following:
■
To save your configuration now and activate later, on the tool bar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
8
After creating a user group, you can use it in the following ways:
■
Use it in a Client VPN tunnel as a remote endpoint
■
Add it to a rule for authentication
■
Use it as the basis for a clientless VPN role
Related information
For further information related to this topic, see the following:
■
“User Group Properties—VPN Authentication tab”
■
“User Group Properties—VPN Network Parameters tab”
■
“Using the Remote Access Tunnel Wizard to create Client VPN tunnels”
■
“Manually configuring a Client VPN tunnel”
■
“Using roles to assign rules to users”
Importing users and user groups
For corporations that have many users or user groups, it can be time consuming to manually create
every record. To help save time when entering user or user group information, you can use the security
gateway’s import feature if you already have the information stored elsewhere and can easily convert
it into one of the security gateway’s supported formats.
The import feature lets you add and update user passwords, authentication keys, and mobile data from
an import file that you create. The import feature is particularly useful if you are introducing a new
Symantec security gateway into an environment with a great deal of established user account
information.
If you upgrade from Symantec Clientless VPN Gateway v5.0 and have users and user groups defined in
an LDIF file, you can import them during the upgrade process.
See the
Symantec Gateway Security 5000 Series v3.0 Installation Guide.
Importing users
Using the Import Users selection on the File menu, you can add users to the security gateway that you
can then use for rules and authentication. By converting user account data into a specific format that
the security gateway understands, you can import this information without re-keying. Importing users
lets you copy and update user passwords, authentication keys, and mobile data from an intermediate
file that you create called pkimpuser. You can find a sample pkimpuser file in the /var/lib/sg directory.
The file is called pkimpuser.sample.
Note:
There is a minimum memory requirement of 2.25 KB for importing each user.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...