
449
Enabling remote access with clientless VPN
Ensuring client compliance for clientless VPN users
Related information
For further information related to this topic, see the following:
■
“Secure Desktop Mail Access Properties—General tab”
■
Ensuring client compliance for clientless VPN users
The client compliance feature of the security gateway lets you put restrictions on computers that
connect through the VPN features of the security gateway to the internal network. By requiring
computers that connect to the VPN to be secured or else be denied access, you can minimize the risk of
opening up your network to remote machines.
A client-compliance profile comprises both the various security criteria that a user’s client computer
must satisfy and also any security actions that either the client or security gateway should perform at
log on and afterward.
Prerequisites
None
To ensure client compliance
1
In the SGMI, in the left pane, under Policy, click
Client Compliance
.
2
In the right pane, in the Client Compliance window, do the following:
Periodically check
compliance
Check this option to enable a compliance check interval.
This option is checked by default.
Check interval
(minutes)
If Periodically check compliance is enabled, type the number of minutes between
automatic client compliance checks. The default is 10 minutes.
Require Symantec
Client Firewall
Check this option to require that clients have Symantec Client Firewall installed and
enabled. This option is checked by default.
Note:
If the Symantec Client Firewall has just been turned on, the security gateway may
not recognize it immediately.
Require auto-protect Check this option to require that the antivirus auto-protect feature is enabled. This
option is checked by default.
Require recent
system scan
Check this option to require that a system antivirus scan is performed periodically. This
option is checked by default.
Last scan within
(days)
If Require recent system scan is enabled, type the number of days between automatic
system scans. The default is 7 days.
Require latest version
of scanning engine
Check this option to require the latest version of the antivirus scanning engine. This
option is disabled by default.
Require latest virus
definitions
Check this option to require that the latest virus definitions be available. This option is
unchecked by default.
Query servers every
... minutes
Type in the number of minutes between antivirus server queries.
The default is 10 minutes.
Primary antivirus
server
Specify the primary antivirus server by selecting it from the drop-down list.
User name
Type the user name for antivirus server access, if required.
Password
Type the password for antivirus server access, if required.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...