451
Enabling remote access with clientless VPN
Specifying the SSL cipher suite for data encryption
3
In the Clientless VPN Role Properties dialog box, on the General tab, in the Client compliance level
drop-down list, select the action to take against non-compliant clients.
4
Click
OK
.
5
Optionally, do one of the following:
■
To save your configuration and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
“Clientless VPN Role Properties—General tab”
■
“Applying client compliance to user groups”
Specifying the SSL cipher suite for data encryption
Data that passes between the clientless VPN client and the security gateway is encrypted using SSL
cipher suites. The client and server negotiate the most secure cipher suite that each end of the
connection supports.
The cipher suites that are available are defined by RFC and cannot be modified; however, you can
specify which cipher suites are used to protect data for your security gateway.
Prerequisites
None.
To specify the SSL cipher suite for data encryption
1
In the SGMI, in the left pane, click
Policy Parameters
.
2
In the right pane, under SSL Cipher Suites, in the Available list, select one or more cipher suites.
3
Click the right (>>) arrow button to move them to the Selected list.
4
To remove cipher suites from the Selected list, select them and then click the left (>>) arrow
button.
5
To move a cipher suite in the Selected list, select it, and then click either the up (
^^)
or down (vv)
arrow buttons to move it in the list.
The order of cipher suites in the list determines the order in which they are considered during
tunnel negotiations.
6
Optionally, do one of the following:
■
To save your configuration and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...