![Vasco aXsGUARD Gatekeeper How To Do Download Page 25](http://html1.mh-extra.com/html/vasco/axsguard-gatekeeper/axsguard-gatekeeper_how-to-do_855712025.webp)
System-Wide Firewall Rights:
System-Wide Firewall Rights apply to all users
in the aXsGUARD Gatekeeper network. Since connected PPTP VPN users are
considered a part of the secure network zone, it is of utmost importance to
restrict the System-Wide Firewall Rights as much as possible. The default
aXsGUARD Gatekeeper System-Wide Firewall Policies (
stat-sec
and
stat-z-fix
)
provide appropriate security for PPTP VPN access. However, you can overrule
these default Policies simply by creating custom Firewall Policies which deny the
default traffic. The created Firewall Policies should then be added to the Group’s
or User’s VPN & RAS Firewall settings (explained further). This solution allows
you to:
• Maintain any changes you have made to System-Wide Firewall Policies.
• To implement even stricter Firewall Policies than the system default
policies.
A list of aXsGUARD Gatekeeper Firewall Rules that are active by default is
available in the Firewall How To. This document can be accessed via the on-
screen
Documentation
button in the Administrator Tool. You can also click on a
Firewall Rule / Policy to view its contents.
User / Group Firewall Rights.
As mentioned in
Section 2.6, “Firewalls and
PPTP”
, VASCO highly recommends the use of a strong client-side firewall and
the creation of dedicated Firewall Policies for PPTP VPN access on the aXsGUARD
Gatekeeper. A predefined Firewall Policy,
fwd-access-lan
, is available in case
administrators choose not to create their own Firewall Policies. This Policy allows
all outbound network traffic from the aXsGUARD Gatekeeper’s secure LAN
interface. This being said, VASCO strongly recommends to create your own PPTP
Firewall Policies.
To adjust a user’s VPN Firewall settings:
1. Navigate to Users & Groups ⇒ Users.
2. Click on the appropriate user name.
3. Select the
Firewall
tab and adjust the VPN & RAS Policy Mode as explained
in the table below.
4. Update your settings.
Figure 3.6. Automatic Activation of Firewall Rules
3.6.3. Firewall Rights
© VASCO Data Security 2011
24