Configuration Settings 29
Enabling SSL for Administrators and Users
The
BASIC
>
Administration
page allows you to modify various settings related to SSL (https) access
to the Web interface for your Barracuda SSL VPN. SSL certificates are configured and uploaded
from the
BASIC
>
SSL Certificate
page
SSL not only ensures that your passwords are encrypted, but also ensures that all data transmitted to
and received from the administration interface is encrypted as well. All Barracuda SSL VPNs support
SSL access without any additional configuring. However, some sites may wish to enforce using a
secured connection to access the Web interface, or prefer to use their own trusted certificates.
To enforce SSL-only access:
1.
Go to the
BASIC
>
Administration
page. The
Appliance Web Interface
section should already
have the Web Interface HTTP Port and the Web Interface HTTPS/SSL Port that you have
configured in entered in step 4c of
Configure Administrative Settings
on page 22).
2.
Set the
HTTPS/SSL Access Only
field to
Yes
. Setting this to
No
will still allow the Barracuda
SSL VPN to accept non-SSL connections..
3.
Click
Save Changes
to save and activate your changes.
If you wish to change the certificate that is used, you must first create and upload it on the
BASIC
>
SSL Certificate
page, then change the
Certificate Type
in the
SSL Certificate Configuration
section.
The Barracuda SSL VPN supports the following types of certificates:
•
Default (Barracuda Networks)
certificates are signed by Barracuda Networks. On some
browsers, these may generate some benign warnings which can be safely ignored. No additional
configuration is required to use these certificates, and are provided free of charge as the default
type of certificate.
•
Private (self-signed)
certificates provide strong encryption without the cost of purchasing a
certificate from a trusted Certificate Authority (CA). These certificates are created by providing
the information requested in the
Certificate Generation
section of the
BASIC
>
SSL Certificate
page. You may also want to download the Private Root Certificate and import it into your
browser, to allow it to verify the authenticity of the certificate and prevent any warnings that
may come up when accessing the Web interface.
•
Trusted (signed by a trusted CA)
certificates are issued by trusted Certificate Authorities
(CA), and must be purchased from them separately with a Certificate Signing Request (CSR).
This can be downloaded after providing the information requested in the
Certificate
Generation
section of the
BASIC
>
SSL Certificate
page. Once you have received the
certificate and key from the CA, you must upload both items to the Barracuda SSL VPN from
the
Trusted Certificate
section of that same page. The certificate will be in effect as soon as the
upload is completed.
Note
The SSL configuration referred to here is related only for the Web-based administrative interface.
There is no need to explicitly configure SSL for traffic between the Barracuda SSL VPN and your
email servers.
Содержание SSL VPN
Страница 8: ...viii Barracuda SSL VPN Administrator s Guide...
Страница 34: ...34 Barracuda SSL VPN Administrator s Guide...
Страница 76: ...76 Barracuda SSL VPN Administrator s Guide...
Страница 94: ...94 Barracuda SSL VPN Administrator s Guide...
Страница 98: ...98 Barracuda SSL VPN Administrator s Guide...
Страница 104: ...104 Barracuda SSL VPN Administrator s Guide...
Страница 110: ...110 Barracuda SSL VPN Administrator s Guide...