398
Providing remote access using VPN tunnels
Ensuring compliance of remote Client VPN computers
3
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
4
After configuring client compliance, you can apply it to the following:
■
Clientless VPN roles
■
User groups
Related information
For further information related to this topic, see the following:
■
■
“Applying client compliance to clientless VPN roles”
■
“Applying client compliance to user groups”
Applying client compliance to user groups
You can control the action taken against non-compliant clients. Three possible actions can be taken:
In the Warn and Deny cases, a message is displayed explaining in what way the client is non-compliant,
based on the selections made in the Client Compliance window.
Prerequisites
Complete one of the following tasks before beginning this procedure:
■
“Ensuring compliance of remote Client VPN computers”
To apply the client compliance policy
1
In the SGMI, in the left pane, under Assets, click
Users
.
2
In the right pane, on the User Groups tab, select the user group to which you want to apply the
client compliance policy, and then click
Properties
.
3
In the User Group Properties dialog box, on the VPN Authentication tab, in the Enforce client
compliance drop-down list, select the level of compliance you want to apply.
4
Click
OK
.
User name
Type the user name for antivirus server access, if required.
Password
Type the password for antivirus server access, if required.
Allow access to
antivirus and/or
LiveUpdate servers
when non-compliant
Check this option to allow antivirus server and LiveUpdate server access to non-
compliant clients.
This option also allows clients to access antivirus servers via DNS or WINS ports.
LiveUpdate server
Select the LiveUpdate server. Ensure that the LiveUpdate server is accessible through
the tunnel.
Warn
Inform the client of the non-compliance, but allow access anyway.
Deny
Deny access. If the Allow access to antivirus and/or LiveUpdate servers on non-
compliance option is checked, access is denied to any systems except antivirus and
LiveUpdate servers.
Ignore
Bypass compliance requirements.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...