12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the Firebox as an Authentication Server4 To add a new user, click Add below the <strong>User</strong>s list.The Setup Firebox <strong>User</strong> dialog box appears.5 Type the name and the passphrase you want the person to use to authenticate to the Firebox.When this passphrase is set, you cannot see the passphrase in simple text again. If you lose the passphrase, you mustset a new passphrase.6 To add the user to a group, select the group name in the Available list. Click the double arrow thatpoints left to move the name to the Member list.You can also double-click the group name.7 Add the user to the PPTP-<strong>User</strong>s group if you want to use the PPTP-<strong>User</strong>s group in a service.8 After you add the user to selected groups, click OK.The user is added to the user list. You can then add more users.9 To close the Setup Firebox <strong>User</strong> dialog box, click OK.The Firebox <strong>User</strong>s tab appears with a list of the new users.10 After you add all necessary users and groups, click OK. At this time, you can use the users andgroups to configure policies and authentication.Using a local user account for Firewall user, PPTP, and MUVPN authenticationAny user can authenticate as a Firewall user, PPTP user, or MUVPN user, and open a PPTP or MUVPN tunnelif PPTP or MUVPN is enabled on the appliance. However, after an authentication or tunnel has beensuccessfully established, users can send traffic through the VPN tunnel only if the traffic is allowed by apolicy on the Firebox. For example, an MUVPN-only user can send traffic through an MUVPN tunnel, butnot a PPTP tunnel even though the user can authenticate and bring up a PPTP tunnel.1 Enable and configure firewall user authentication, MUVPN, and PPTP to use local accounts.2 Create appropriate policies for these authentication types.3 Associate an user account to each authentication group (FW-<strong>User</strong>s, PPTP-<strong>User</strong>s, MUVPN-<strong>User</strong>s). Alsocreate an account that does not belong to any group.4 Deploy the configuration to the Firebox.5 Use a web browser, PPTP client, and MUVPN client to authenticate to the Firebox with each of theseuser accounts.126 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!