WatchGuard Technologies Water Heater SSL VPN User Manual

Browse online or download User Manual for Software WatchGuard Technologies Water Heater SSL VPN. WatchGuard Technologies Water Heater SSL VPN User's Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 198
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - Gateway Administration Guide

WatchGuard®Firebox®SSL VPN Gateway Administration Guide Firebox SSL VPN Gateway

Page 2 - ABOUT WATCHGUARD

x WatchGuard SSL VPN GatewayLaunching the v 5.5 Administration Tool ...

Page 3 - Contents

Configuring Properties for a User Group90 Firebox SSL VPN GatewayConfiguring Properties for a User GroupGroup properties include configuring access, n

Page 4

Administration Guide 91Configuring Properties for a User Group NoteIf you want to close a connection and prevent a user or group from reconnecting au

Page 5 - Admin Guide v

Configuring Properties for a User Group92 Firebox SSL VPN Gatewaysupported and do not run. If the domain controller cannot be contacted, the Firebox

Page 6

Administration Guide 93Configuring Properties for a User GroupConfiguring Web Session Time-Outs When a user is logged on to the Firebox SSL VPN Gatewa

Page 7 - Admin Guide vii

Configuring Properties for a User Group94 Firebox SSL VPN Gateway2 On the General tab, under Application Options, select Deny applications without pol

Page 8

Administration Guide 95Configuring Properties for a User GroupChoosing a portal page for a groupBy default, all users log on to the Firebox SSL VPN Ga

Page 9 - Admin Guide ix

Configuring Resources for a User Group96 Firebox SSL VPN Gateway NoteClient certificate configuration is not available for the default user group.To

Page 10

Administration Guide 97Configuring Resources for a User Groupa network resource specifying the networks to which users can connect. If you have a rest

Page 11 - VPN Gateway

Configuring Resources for a User Group98 Firebox SSL VPN Gateway• Kiosk resources that define how the user can log on and which file shares and applic

Page 12 - Document Conventions

Administration Guide 99Configuring Resources for a User GroupTo configure resource access control for a group1 Click the Access Policy Manager tab.2 I

Page 13 - Administration Guide 3

Administration Guide 1CHAPTER 1 Getting Started with Firebox SSL VPN GatewayThis chapter describes who should read the Firebox SSL VPN Gateway Adminis

Page 14 - Instant Answers

Configuring Resources for a User Group100 Firebox SSL VPN Gateway• You can further restrict access by specifying a port and protocol for an IP address

Page 15 - WatchGuard Users Forum

Administration Guide 101Configuring Resources for a User Group• Deny rules take precedence over allow rules. This enables you to allow access to a ran

Page 16 - Technical Support

Configuring Resources for a User Group102 Firebox SSL VPN GatewayTo add an application policy to a group1 On the Access Policy Manager tab, in the rig

Page 17 - Training and Certification

Administration Guide 103Configuring Resources for a User GroupTo create a file share resource1 Click the Access Policy Manager tab.2 In the right pane

Page 18 - 8 Firebox SSL VPN Gateway

Configuring Resources for a User Group104 Firebox SSL VPN Gateway3 To add a file share, under File Share Resources, drag the resource to Shares under

Page 19 - Overview

Administration Guide 105Configuring Resources for a User Group8 If you selected Process Rule, do the following: -Click Process Rule. -In Process Name,

Page 20 - 10 Firebox SSL VPN Gateway

Setting the Priority of Groups106 Firebox SSL VPN Gateway2 In the right pane, right-click End Point Policies and then click New End Point Policy. 3 Ty

Page 21 - New Features

Administration Guide 107Setting the Priority of GroupsThe following two settings are unioned together. For these settings, they are combined among all

Page 22 - 12 Firebox SSL VPN Gateway

Setting the Priority of Groups108 Firebox SSL VPN Gateway

Page 23 - Features

Administration Guide 109CHAPTER 7 Creating and Installing Secure CertificatesThe Firebox SSL VPN Gateway uses certificates for authentication. In the

Page 24

Document Conventions2 Firebox SSL VPN GatewayDocument ConventionsFirebox SSL VPN Gateway documentation uses the following typographic conventions for

Page 25

Digital Certificates and Firebox SSL VPN Gateway Operation110 Firebox SSL VPN Gateway• Install a PEM certificate and private key from a Windows comput

Page 26 - The User Experience

Administration Guide 111Overview of the Certificate Signing Requestprivate key from tampering and it is also required when restoring a saved configura

Page 27 - Deployment and Administration

Overview of the Certificate Signing Request112 Firebox SSL VPN Gateway NoteWhen you save the Firebox SSL VPN Gateway configuration, any certificates

Page 28 - Planning your deployment

Administration Guide 113Overview of the Certificate Signing RequestThe root certificate that is installed on the Firebox SSL VPN Gateway has to be in

Page 29 - Authentication Support

Client Certificates114 Firebox SSL VPN Gateway NoteNote: HyperTerminal is not installed automatically on Windows 2000 Server or Windows Server 2003.

Page 30 - 20 Firebox SSL VPN Gateway

Administration Guide 115Client Certificates Installing Root Certificates Support for most trusted root authorities is already built into the Windows o

Page 31 - Administration Guide 21

Requiring Certificates from Internal Connections116 Firebox SSL VPN Gateway3Click Submit. Requiring Certificates from Internal ConnectionsTo increase

Page 32 - 22 Firebox SSL VPN Gateway

Administration Guide 117CHAPTER 8 Working with Client ConnectionsClients can access resources on the corporate network by connecting through the Fireb

Page 33

Using the Access Portal118 Firebox SSL VPN GatewayIf clients are using Mozilla Firefox to connect, pages that require ActiveX, such as the pre-authent

Page 34 - 24 Firebox SSL VPN Gateway

Administration Guide 119Connecting from a Private Computerthe computer is started, users do not have to do anything to create the connection, provided

Page 35 - To configure a proxy server

Administration Guide 3LiveSecurity Service Broadcastslearn more about your WatchGuard Firebox® and network security, or find a WatchGuard Certified Tr

Page 36 - 26 Firebox SSL VPN Gateway

Connecting from a Private Computer120 Firebox SSL VPN Gateway• The Firebox SSL VPN Gateway terminates the SSL tunnel, accepts any incoming traffic des

Page 37 - Administration Guide 27

Administration Guide 121Connecting from a Private Computerthat remote users can access through the VPN connection. For more information, see “Configur

Page 38 - Using Kiosk Mode

Connecting from a Private Computer122 Firebox SSL VPN Gatewaysends its known local IP address to the server by means of a custom client-server protoco

Page 39 - Administration Guide 29

Administration Guide 123Connecting from a Private Computer An email template is provided that includes the information discussed in this section. The

Page 40 - 30 Firebox SSL VPN Gateway

Connecting from a Private Computer124 Firebox SSL VPN GatewayThe Secure Access Client dialog box with the pop-up menu showing Advanced Options4 Under

Page 41 - Configuring Basic Settings

Administration Guide 125Connecting from a Private ComputerTo view the Connection LogThe Connection Log contains real-time connection information that

Page 42 - Downloads Tab

Connecting from a Public Computer126 Firebox SSL VPN GatewayConfiguring Secure Access Client to Work with Non-Administrative UsersIf a user is not log

Page 43 - Using the Serial Console

Administration Guide 127Connecting from a Public Computer• Firefox Web browser. You configure by group whether or not to include the Firefox browser a

Page 44 - Using the Administration Tool

Connecting from a Public Computer128 Firebox SSL VPN GatewayTo create and configure a kiosk resource 1 Click the Access Policy Manager tab. 2 In the r

Page 45 - Unknown Status

Administration Guide 129Client Applications2 Select a file share from File Share Resources and drag it to Shares under File shares in the kiosk resour

Page 46 - Managing Licenses

LiveSecurity Service Self Help Tools4 Firebox SSL VPN GatewayNew from WatchGuardWhen WatchGuard releases a new product, we first tell you — our custom

Page 47 - To install a license file

Client Applications130 Firebox SSL VPN GatewayFirefox Web Browser The Firefox Web browser allows users to connect to the Internet when they are logged

Page 48 - Using Portal Pages

Administration Guide 131Client ApplicationsTo use the SSH client1 From the portal page, choose A public computer and log on.2 In the Web browser, clic

Page 49

Supporting Secure Access Client132 Firebox SSL VPN GatewayTo use Gaim1 From the portal page, choose A public computer and log on.2 In the Web browser,

Page 50 - Using the ActiveX Control

Administration Guide 133Managing Client ConnectionsAn email template is provided that includes the information discussed in this section. The template

Page 51 - Web site

Managing Client Connections134 Firebox SSL VPN GatewayClosing a connection to a resourceWithout disrupting a user’s VPN connection, you can temporaril

Page 52 - Secure Kiosk Access

Administration Guide 135Managing Client Connections2 In the left pane, right-click a group and click Properties. 3 On the General tab, under Session o

Page 53 - Administration Guide 43

Managing Client Connections136 Firebox SSL VPN Gateway

Page 54

Administration Guide 137APPENDIX A Firebox SSL VPN Gateway Monitoring and TroubleshootingThe following topics describe how to use Firebox SSL VPN Gate

Page 55 - Administration Portal

Viewing and Downloading System Message Logs138 Firebox SSL VPN Gateway3Click Logging/Settings.4Under Gateway Log, click Display Logging Window.The log

Page 56 - Allowing ICMP traffic

Administration Guide 139Enabling and Viewing SNMP LogsTo view or download the log, go to the Logging > Configuration tab and click Download W3C Log

Page 57 - Gateway Network Connections

Administration Guide 5WatchGuard Users ForumAdvanced FAQsThe Advanced FAQs (frequently asked questions) give you important information about configura

Page 58 - General Networking

Viewing System Statistics140 Firebox SSL VPN GatewayTo obtain SNMP data for the Firebox SSL VPN Gateway through Multi Router Traffic Grapher (in UNIX)

Page 59 - Administration Guide 49

Administration Guide 141Recovering from a Failure of the Firebox SSL VPN Gatewaybottom right corner, you can view process and network activity levels;

Page 60 - Name Service Providers

Recovering from a Failure of the Firebox SSL VPN Gateway142 Firebox SSL VPN Gateway• apply the v 5.5 software updateReinstalling v 4.9 application sof

Page 61 - Dynamic and Static Routing

Administration Guide 143TroubleshootingTo upgrade to v 5.5.1 In the v5.0 Administration Tool, click the Firebox® SSL VPN Gateway Cluster tab.2On the A

Page 62 - Configuring Dynamic Routing

Troubleshooting144 Firebox SSL VPN GatewayBy default, the Firebox SSL VPN Gateway passes only the user name and password to the Web Interface. To corr

Page 63 - Configuring a Static Route

Administration Guide 145TroubleshootingDefining Accessible NetworksIn the Accessible Networks field on the Global Cluster Policies tab, up to 24 subne

Page 64 - Static Route Example

Troubleshooting146 Firebox SSL VPN GatewayInternal FailoverIf internal failover is enabled and the administrator is connected to the Firebox SSL VPN G

Page 65 - Configuring Internal Failover

Administration Guide 147TroubleshootingDevices Cannot Communicate with the Firebox SSL VPN GatewayVerify that the following are correctly set up:• The

Page 66 - Controlling Network Access

Troubleshooting148 Firebox SSL VPN GatewayClient Connections from a Windows Server 2003 If a connection to the Firebox SSL VPN Gateway is made from a

Page 67 - Enabling Split Tunneling

Administration Guide 149APPENDIX B Using Firewalls with Firebox SSL VPN GatewayIf a user cannot establish a connection to the Firebox SSL VPN Gateway

Page 68 - Configuring User Groups

Online Help6 Firebox SSL VPN GatewayThis forum has different categories that you can use to look for information. The Technical Support team controls

Page 69 - Administration Guide 59

BlackICE PC Protection150 Firebox SSL VPN GatewayTo view Secure Access Client status properties Double-click the Secure Access Client connection icon

Page 70 - 60 Firebox SSL VPN Gateway

Administration Guide 151Norton Personal Firewall.Norton Personal FirewallIf you are using the default Norton Personal Firewall settings, you can simpl

Page 71 - Authorization

ZoneAlarm Pro152 Firebox SSL VPN GatewayTo configure the settings, open the Tiny Personal Firewall administration window, click the Advanced button to

Page 72 - 62 Firebox SSL VPN Gateway

Administration Guide 153APPENDIX C Installing Windows CertificatesThe Firebox SSL VPN Gateway includes the Certificate Request Generator to automatica

Page 73 - The Default Realm

Unencrypting the Private Key154 Firebox SSL VPN Gateway12 Click Next to start the installation.After Cygwin installs, you can generate the CSR.These i

Page 74 - Changing Password for Users

Administration Guide 155Converting to a PEM-Formatted CertificateFor information about downloading OpenSSL for Windows, see the SourceForge Web site a

Page 75 - Configuring the Default Realm

Generating Trusted Certificates for Multiple Levels156 Firebox SSL VPN GatewayTo combine the private key with the signed certificate1 Use a text edito

Page 76 - Creating Additional Realms

Administration Guide 157Generating Trusted Certificates for Multiple LevelsIntermediate Certificate 0 Intermediate Certificate 1 Intermediate Certific

Page 77 - Removing Realms

Generating Trusted Certificates for Multiple Levels158 Firebox SSL VPN Gateway

Page 78 - Authentication

Administration Guide 159APPENDIX D Examples of Configuring Network AccessAfter the Firebox SSL VPN Gateway is installed and configured to operate in y

Page 79 - Administration Guide 69

Administration Guide 7Training and CertificationService timeWe try for a maximum response time of four hours.Single Incident Priority Response Upgrade

Page 80 - 70 Firebox SSL VPN Gateway

Scenario 1: Configuring LDAP Authentication and Authorization160 Firebox SSL VPN GatewayBefore reading the examples in this chapter, you should become

Page 81

Administration Guide 161Scenario 1: Configuring LDAP Authentication and Authorization• Determining the Sales and Engineering users who need remote acc

Page 82

Scenario 1: Configuring LDAP Authentication and Authorization162 Firebox SSL VPN GatewayFor example, if the Firebox SSL VPN Gateway operates with the

Page 83 - LDAP authentication

Administration Guide 163Scenario 1: Configuring LDAP Authentication and Authorization• LDAP Server port. The port on which the LDAP server listens for

Page 84 - LDAP Directory” on page 78

Scenario 1: Configuring LDAP Authentication and Authorization164 Firebox SSL VPN GatewayThis task includes these five procedures: • Configuring access

Page 85 - LDAP Authorization

Administration Guide 165Scenario 1: Configuring LDAP Authentication and AuthorizationCreating an LDAP Authentication and Authorization Realm Creating

Page 86

Scenario 1: Configuring LDAP Authentication and Authorization166 Firebox SSL VPN GatewayCreating the Appropriate Groups on the Firebox SSL VPN Gateway

Page 87 - Administration Guide 77

Administration Guide 167Scenario 1: Configuring LDAP Authentication and Authorization4 In Network/Subnet, type these two IP address/subnet pairs for t

Page 88 - 78 Firebox SSL VPN Gateway

Scenario 1: Configuring LDAP Authentication and Authorization168 Firebox SSL VPN Gatewaythe 10.0.20.x resource and allow access to the 10.0.x.x resour

Page 89 - To look up LDAP attributes

Administration Guide 169Scenario 2: Creating Guest Accounts Using the Local Users List5 In the left pane, click the "Email server" network r

Page 90 - 80 Firebox SSL VPN Gateway

Training and Certification8 Firebox SSL VPN Gatewaya certification exam. The training materials include links to books and web sites with more informa

Page 91

Scenario 2: Creating Guest Accounts Using the Local Users List170 Firebox SSL VPN GatewayAn administrator can also create a list of local users on the

Page 92 - Resetting the node secret

Administration Guide 171Scenario 2: Creating Guest Accounts Using the Local Users ListTo create a guest authentication realm for the guest users 1 In

Page 93

Scenario 3: Configuring Local Authorization for Local Users172 Firebox SSL VPN GatewaySilvio and Lisa are authorized to access any resource defined in

Page 94 - 84 Firebox SSL VPN Gateway

Administration Guide 173APPENDIX E Legal and Copyright InformationGNU GENERAL PUBLIC LICENSE FOR LINUX KERNEL AS PROVIDED WITH FIREBOX SSL Firebox SS

Page 95 - Administration Guide 85

174 Firebox SSL VPN Gateway We protect your rights with two steps: (1) copyright the software, and (2) offer you this license which gives you legal p

Page 96 - Changing Password Labels

Administration Guide 175 change. b) You must cause any work that you distribute or publish, that in whole or in part contains or is derived from

Page 97 - Adding Local Users

176 Firebox SSL VPN Gateway be distributed under the terms of Sections 1 and 2 above on a medium customarily used for software interchange; or,

Page 98 - User Group Overview

Administration Guide 177If any portion of this section is held invalid or unenforceable under any particular circumstance, the bal-ance of the section

Page 99 - Creating User Groups

178 Firebox SSL VPN Gateway 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPY-RIGHT HOLDER, OR ANY OTHER PARTY

Page 100 - Forcing Users to Log on Again

Administration Guide 179 This is free software, and you are welcome to redistribute it under certain conditions; type `show c' for details.The

Page 101 - Enabling domain logon scripts

Administration Guide 9CHAPTER 2 Introduction to Firebox SSL VPN GatewayWatchGuard Firebox SSL VPN Gateway is a universal Secure Socket Layer (SSL) vir

Page 102 - Enabling session time-out

180 Firebox SSL VPN Gateway

Page 103 - Setting Application Options

Administration Guide 181IndexAaccess control list 56, 97allow and deny rules 98deny access 15, 58deny access without ACL 57, 88Access Policy Manager t

Page 104 - Enabling IP Pooling

182 Firebox SSL VPN GatewayAuthentication tabLDAP 74authorization 15configuring 61LDAP 65, 73LDAP and RSA/ACE Server 81local users 65RADIUS 69, 72Bbac

Page 105 - 4 Click OK

Administration Guide 183removing 105Ethereal Network Analyzer 141unencrypted traffic 27Ethereal Network Monitor 17external access 15Ffailover 48applia

Page 106 - Global policies

184 Firebox SSL VPN Gatewaypersistence 104Remote Desktop Client 130shared network drives, using 128SSH client 130Telnet 3270 Emulator client 131using

Page 107 - Group resources include:

Administration Guide 185ping 46command 33, 145from xNetTools 141policiesaccess control lists 56IP pooling 94network access 56portal pages 38, 41settin

Page 108 - 98 Firebox SSL VPN Gateway

186 Firebox SSL VPN Gatewayconnection to 28service scanner 141session timeout 15, 88, 92settingsGeneral Networking 47shared network drives 128shared

Page 109 - Defining network resources

Administration Guide 187failover servers 55General Networking 14, 47logging 14, 137managing licenses 15, 36Name Service Providers 14, 47Network Time P

Page 110 - 100 Firebox SSL VPN Gateway

188 Firebox SSL VPN Gateway

Page 111 - Application policies

ii Firebox SSL VPN GatewayADDRESS:505 Fifth Avenue SouthSuite 500Seattle, WA 98104SUPPORT: www.watchguard.com/[email protected]. and C

Page 112 - Deny. Click OK

Overview10 Firebox SSL VPN GatewayAs shown in the following illustration, the Firebox SSL VPN Gateway is appropriate for employees accessing the organ

Page 113 - Configuring kiosk mode

Administration Guide 11New FeaturesThe virtual TCP circuit is using industry standard Secure Socket Layer (SSL) and Transport Layer Security (TLS) enc

Page 114 - 104 Firebox SSL VPN Gateway

New Features12 Firebox SSL VPN GatewaySecure Access Client connectionsThe Secure Access Client included in this release can connect to earlier version

Page 115

Administration Guide 13FeaturesNTLM authentication and authorization support. If your environment includes Windows NT 4.0 domain controllers, the Fire

Page 116 - 106 Firebox SSL VPN Gateway

Features14 Firebox SSL VPN Gateway• Date and time configuration• Certificate generation and installation• Restarting and shutting down the Firebox SSL

Page 117 - Administration Guide 107

Administration Guide 15FeaturesServer UpgradeVPN Gateway Cluster > AdministrationServer RestartVPN Gateway Cluster > AdministrationServer Shut D

Page 118 - 108 Firebox SSL VPN Gateway

The User Experience16 Firebox SSL VPN GatewayFeature SummaryThe following are key Firebox SSL VPN Gateway features:• Universal SSL VPN. Supports all a

Page 119 - Certificates

Administration Guide 17Deployment and AdministrationSecure Access Client by typing a secure Web address in a standard Web browser and providing authen

Page 120 - 110 Firebox SSL VPN Gateway

Planning your deployment18 Firebox SSL VPN GatewayAdministration Desktop also provides access to the Real-Time Monitor, where you can view a list of c

Page 121 - Administration Guide 111

Administration Guide 19Planning for Security with the Firebox SSL VPN GatewayWhen an Firebox SSL VPN Gateway is deployed in the secure network, the Se

Page 122 - 112 Firebox SSL VPN Gateway

Admin Guide iiiContentsCHAPTER 1 Getting Started with Firebox SSL VPN Gateway ... 1Audience ...

Page 123 - Administration Guide 113

Installing the Firebox SSL VPN Gateway for the First Time20 Firebox SSL VPN GatewayDeploying Additional Appliances for Load Balancing and Failover You

Page 124 - Client Certificates

Administration Guide 21Installing the Firebox SSL VPN Gateway for the First Time• The Firebox SSL VPN Gateway FQDN for network address translation (NA

Page 125 - Installing Root Certificates

Installing the Firebox SSL VPN Gateway for the First Time22 Firebox SSL VPN Gateway• [4] Display Log displays the Firebox SSL VPN Gateway log • [5] Re

Page 126 - Wildcard Certificates

Administration Guide 23Installing the Firebox SSL VPN Gateway for the First TimeTo configure TCP/IP Settings Using Network Cables The Firebox SSL VPN

Page 127 - System Requirements

Using the Firebox SSL VPN Gateway24 Firebox SSL VPN GatewayFor information about the relationship between the Default Gateway and dynamic or static ro

Page 128 - Using the Access Portal

Administration Guide 25Using the Firebox SSL VPN Gateway• After downloading the Secure Access Client, the user logs on. When the user successfully aut

Page 129 - Administration Guide 119

Using the Firebox SSL VPN Gateway26 Firebox SSL VPN GatewayEstablishing the Secure TunnelAfter the Secure Access Client is started, it establishes a s

Page 130 - 120 Firebox SSL VPN Gateway

Administration Guide 27Using the Firebox SSL VPN GatewayNAT firewalls maintain a table that allows them to route secure packets from the Firebox SSL V

Page 131 - Administration Guide 121

Using the Firebox SSL VPN Gateway28 Firebox SSL VPN Gatewaywork, no attempt is made by either the client or the server applications to regenerate them

Page 132 - ActiveX Helper

Administration Guide 29Using the Firebox SSL VPN Gatewaypublic address. The external public address ensures that the redirected client returns to the

Page 133 - Administration Guide 123

iv WatchGuard SSL VPN GatewayDisable kiosk mode ...

Page 134 - 124 Firebox SSL VPN Gateway

Using the Firebox SSL VPN Gateway30 Firebox SSL VPN Gateway

Page 135 - Administration Guide 125

Administration Guide 31CHAPTER 3 Configuring Basic SettingsThis chapter describes Firebox SSL VPN Gateway basic administration, including connecting t

Page 136 - Connections Using Kiosk Mode

Firebox SSL VPN Gateway Administration Desktop32 Firebox SSL VPN GatewayFirebox SSL VPN Gateway Administration DesktopThe Firebox SSL VPN Gateway Admi

Page 137 - To enable kiosk mode

Administration Guide 33Using the Serial Console• Download a sample email for usersAdmin Users TabThe Firebox SSL VPN Gateway has a default administrat

Page 138 - 128 Firebox SSL VPN Gateway

Using the Administration Tool34 Firebox SSL VPN GatewayTo open the serial console1 Connect the RS232 cable to the serial port on the Firebox SSL VPN G

Page 139 - Client Applications

Administration Guide 35Publishing Settings to Multiple Firebox SSL VPN Gateways7In Username and Password, type the Firebox SSL VPN Gateway administrat

Page 140 - SSH Client

Managing Licenses36 Firebox SSL VPN GatewayFirebox SSL VPN Gateway Administration Tool. To apply these license files, see “Managing Licenses” on page

Page 141 - Gaim Instant Messenging

Administration Guide 37Managing LicensesDo not overwrite any .lic files in the license directory. If another file in that directory has the same name,

Page 142 - 132 Firebox SSL VPN Gateway

Blocking External Access to the Administration Portal38 Firebox SSL VPN Gateway5 In a Web browser, type the address of the Firebox SSL VPN Gateway usi

Page 143 - Managing Client Connections

Administration Guide 39Downloading and Working with Portal Page TemplatesBy default, users see a WatchGuard Firebox SSL VPN Gateway portal page when t

Page 144 - Disabling and enabling a user

Admin Guide vUsing the Serial Console ...

Page 145

Downloading and Working with Portal Page Templates40 Firebox SSL VPN GatewayTo download the portal page templates to your local computer1 In the Fireb

Page 146 - 136 Firebox SSL VPN Gateway

Administration Guide 41Enabling Portal Page AuthenticationTo install a custom portal page or image on the Firebox SSL VPN Gateway1Click the Portal Pag

Page 147 - Firebox SSL VPN Gateway

Linking to Clients from Your Web Site42 Firebox SSL VPN Gateway<object id="Net6Launch" type="application/x-oleobject" classid=&

Page 148 - Field Description

Administration Guide 43Connecting Using a Web Addresstication policy check fails, the users receive an error message instructing them to contact their

Page 149

Saving and Restoring the Configuration44 Firebox SSL VPN GatewaySaving and Restoring the ConfigurationWhen you upgrade the Firebox SSL VPN Gateway, al

Page 150 - Viewing System Statistics

Administration Guide 45Restarting the Firebox SSL VPN Gateway2In Upload a Server Upgrade or Saved Config, click Browse. 3 Locate the upgrade file that

Page 151 - Administration Guide 141

Allowing ICMP traffic46 Firebox SSL VPN GatewayTo change the system date and time1 In the Administration Tool, click the VPN Gateway Cluster tab, sele

Page 152 - Upgrading to SSL v 5.5

Administration Guide 47CHAPTER 4 Configuring Firebox SSL VPN Gateway Network ConnectionsThe Firebox SSL VPN Gateway has two network adapters that can

Page 153 - Troubleshooting

General Networking48 Firebox SSL VPN Gateway•The Routes tab is where dynamic and static routes are configured•The Failover Servers tab is where multip

Page 154 - Other Issues

Administration Guide 49General NetworkingThe Firebox SSL VPN Gateway in the DMZ.For more information, see “Connecting to a Server Load Balancer” on pa

Page 155 - Administration Guide 145

vi WatchGuard SSL VPN GatewayAllowing ICMP traffic ...

Page 156 - 146 Firebox SSL VPN Gateway

Name Service Providers50 Firebox SSL VPN Gateway NoteIP pooling is configured per groups, as described in “Enabling IP Pooling” on page 94.Name Servi

Page 157 - Administration Guide 147

Administration Guide 51Dynamic and Static Routing3Under Edit the HOSTS file, in IP address, enter the IP address that you want to associate with an FQ

Page 158 - WINS Entries

Dynamic and Static Routing52 Firebox SSL VPN GatewayConfiguring Dynamic RoutingWhen dynamic routing is selected, the Firebox SSL VPN Gateway operates

Page 159

Administration Guide 53Dynamic and Static Routing5 In the text box, type a text string that is an exact, case-sensitive match to the authentication st

Page 160 - McAfee Personal Firewall Plus

Dynamic and Static Routing54 Firebox SSL VPN Gateway8On the General Networking tab, click Submit.The route name appears in the Static Routes list.To t

Page 161 - Tiny Personal Firewall

Administration Guide 55Configuring Firebox SSL VPN Gateway FailoverTo set up the static route, you need to establish the path between the eth1 adapter

Page 162 - ZoneAlarm Pro

Controlling Network Access56 Firebox SSL VPN Gatewaynect to port 9001 when you are logged on from an external connection, configure IP pools and conne

Page 163 - To install Cygwin

Administration Guide 57Enabling Split TunnelingYou can change the default operation so that user groups are denied network access unless they are allo

Page 164 - Unencrypting the Private Key

Denying Access to Groups without an ACL58 Firebox SSL VPN GatewayWhen you enable split tunneling, you must enter a list of accessible networks on the

Page 165 - 1 Run the command:

Administration Guide 59Improving Voice over IP ConnectionsTo deny access to user groups without an ACL1Click the Global Cluster Policies tab.2Under Ac

Page 166 - 156 Firebox SSL VPN Gateway

Admin Guide viiTo disable Firebox SSL VPN Gateway authentication ...68SafeWord Premier

Page 167 - Intermediate Certificate 2

Improving Voice over IP Connections60 Firebox SSL VPN Gateway NoteIf the Improving Voice over IP Connections setting is not selected, the UDP traffic

Page 168 - 158 Firebox SSL VPN Gateway

Administration Guide 61CHAPTER 5 Configuring Authentication and AuthorizationThe Firebox SSL VPN Gateway supports several authentication types includi

Page 169 - Administration Guide 159

Configuring Authentication and Authorization62 Firebox SSL VPN GatewayCommunications between the Firebox SSL VPN Gateway and authentication servers.If

Page 170 - 160 Firebox SSL VPN Gateway

Administration Guide 63Configuring Authentication and AuthorizationConfiguring Authentication without Authorization The Firebox SSL VPN Gateway can be

Page 171 - Administration Guide 161

Configuring Authentication and Authorization64 Firebox SSL VPN GatewayConfiguring Local UsersYou can create user accounts locally on the Firebox SSL V

Page 172 - 162 Firebox SSL VPN Gateway

Administration Guide 65Changing the Authentication Type of the Default RealmTo change a user’s password1On the Access Policy Manager tab, right-click

Page 173 - Resources

Changing the Authentication Type of the Default Realm66 Firebox SSL VPN Gateway3On the Action menu, select Remove Default realm.A warning message appe

Page 174 - 164 Firebox SSL VPN Gateway

Administration Guide 67Using SafeWord for AuthenticationRemoving RealmsIf you are retiring an authentication server or removing a domain server, you c

Page 175 - Administration Guide 165

Using SafeWord for Citrix or SafeWord RemoteAccess for Authentication68 Firebox SSL VPN GatewayConfigure a SafeWord realm to authenticate users. The F

Page 176 - 166 Firebox SSL VPN Gateway

Administration Guide 69Using RADIUS Servers for Authentication and AuthorizationIf you are already using SafeWord for Citrix or SafeWord RemoteAccess

Page 177 - Administration Guide 167

viii WatchGuard SSL VPN GatewayEnabling session time-out ...

Page 178 - 168 Firebox SSL VPN Gateway

Using RADIUS Servers for Authentication and Authorization70 Firebox SSL VPN Gateway•Type is the vendor-assigned attribute number.• Attribute name is t

Page 179 - Administration Guide 169

Administration Guide 71Using RADIUS Servers for Authentication and Authorization18 In the Add Attributes dialog box, select Vendor-Specific and click

Page 180 - 170 Firebox SSL VPN Gateway

Using RADIUS Servers for Authentication and Authorization72 Firebox SSL VPN GatewayTo specify RADIUS server authentication1Click the Authentication ta

Page 181 - Creating Local Users

Administration Guide 73Using LDAP Servers for Authentication and AuthorizationRADIUS authentication. If you synchronize configurations among several F

Page 182 - 172 Firebox SSL VPN Gateway

Using LDAP Servers for Authentication and Authorization74 Firebox SSL VPN GatewayThis table contains examples of the base dnThe following table contai

Page 183 - Administration Guide 173

Administration Guide 75LDAP Authorization8 Select Allow Unsecure Traffic to allow unsecure LDAP connections.When this check box is clear, all LDAP con

Page 184 - 174 Firebox SSL VPN Gateway

LDAP Authorization76 Firebox SSL VPN GatewayGroup memberships from group objects working evaluationsLDAP servers that evaluate group memberships from

Page 185 - Administration Guide 175

Administration Guide 77LDAP AuthorizationThe LDAP Server port defaults to 389. If you are using an indexed database, such as Microsoft Active Director

Page 186 - 176 Firebox SSL VPN Gateway

LDAP Authorization78 Firebox SSL VPN GatewayFor Active Directory, the group name specified as cn=groupname is required. The group name that is defined

Page 187 - Administration Guide 177

Administration Guide 79Using RSA SecurID for AuthenticationHostHost name or IP address of your LDAP server.PortDefaults to 389. Base DNYou can leave t

Page 188 - 178 Firebox SSL VPN Gateway

Admin Guide ixUsing the Access Portal ...

Page 189 - Administration Guide 179

Using RSA SecurID for Authentication80 Firebox SSL VPN GatewayThe Firebox SSL VPN Gateway supports RSA ACE/Server Version 5.2 and higher. The Firebox

Page 190 - 180 Firebox SSL VPN Gateway

Administration Guide 81Using RSA SecurID for Authentication8 To create the configuration file for the new or changed Agent Host, go to Agent Host >

Page 191

Using RSA SecurID for Authentication82 Firebox SSL VPN GatewayConfiguring RSA Settings for a ClusterIf you have two or more appliances configured as a

Page 192

Administration Guide 83Using RSA SecurID for Authentication NoteNote: If you are configuring double-source authentication, click Two Source and then

Page 193

Using RSA SecurID for Authentication84 Firebox SSL VPN Gateway NoteNote: When 0 (zero) is entered as the port, the Access Gateway attempts to automat

Page 194

Administration Guide 85Configuring Double-Source AuthenticationYou can prevent the storage of one-time passwords in cache, which forces the user to en

Page 195

Configuring Double-Source Authentication86 Firebox SSL VPN Gatewayand passcode first and then the LDAP password second. Whatever is typed in the first

Page 196

Administration Guide 87CHAPTER 6 Adding and Configuring Local Users and User Groups User groups define the resources the user has access to when conne

Page 197

User Group Overview88 Firebox SSL VPN Gateway5 All users are members of the Default resource group. To add a user to another group, under Local Users,

Page 198 - 188 Firebox SSL VPN Gateway

Administration Guide 89Creating User GroupsGroup resources include:• Network resources that define the networks to which clients can connect.• Applica

Comments to this Manuals

No comments