Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 153
VPN Remote
Access Attribute
Description
Remote Access
port
Reserve port 443
for port
forwarding
The default remote access port is port 443. If there is a conflict with
another server using this port number, configure a different
Remote
access port
. You must change the default remote access port if the
Check Point VPN client, Mobile client, or SSL VPN remote access
methods are enabled as they use port 443 by default. If you change the
default port number 443, make sure to select
Reserve port 443 for port
forwarding
.
SNX keep-alive
interval
Indicates the time (in seconds) between the SSL Network Extender client
keep-alive packets.
SNX re-
authentication
timeout
Indicates the time (in minutes) between re-authentication of SSL Network
Extender remote access users.
SNX support
3DES
Indicates if the 3DES encryption algorithm will be supported in SSL
clients as well as the default algorithms.
SNX support
RC4
Indicates if the RC4 encryption algorithm is supported in SSL clients as
well as the default algorithms.
SNX uninstall
This parameter lets you configure under which conditions the SSL
Network Extender client uninstalls itself. The options are: Do not uninstall
automatically (recommended default), always uninstall upon
disconnection, and ask the user upon disconnection.
SNX upgrade
This parameter lets you configure under which conditions the SSL
Network Extender client installs itself. The options are: Do not upgrade
automatically, always upgrade, and ask the user (default).
Topology
updates manual
interval
Indicates the manually configured interval (in hours) for topology updates
to the clients. Applicable only if the override settings is set to true.
Topology
updates override
Indicates if the configured topology updates settings override the default
'once a week' policy.
Topology
updates upon
startup only
Indicates if topology updates occur only when the client starts. Applicable
only if the override settings is set to true.
Verify device
certificate
The remote access client verifies the device's certificate against
revocation list.
block user if
belongs to at
least one group
without
permission
Indicates if strict group permissions are enabled - user will not have
remote access permission if belongs to at least one group without remote
access permission.
Table: VPN Remote Access Attributes (continued)