WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

WatchGuard VPN SolutionsSplit tunneling decreases security, but does increase performance. If you use split tunneling, remoteusers must have personal firewalls for computers behind the VPN endpoint.WatchGuard VPN SolutionsWatchGuard® System Manager includes this software to create tunnels:• Remote User VPN (RUVPN) with PPTP• Mobile User VPN (MUVPN) with IPSec• Branch Office VPN (BOVPN) with IPSec, which uses Policy Manager to manually configure thetunnel settings• Branch Office VPN (BOVPN) with IPSec, which uses WatchGuard System Manager to automaticallyconfigure the tunnel settings.WatchGuard includes different types of encryption for the different types of VPN tunnels you can create.BOVPN allows Data Encryption Service (DES) with a 56-bit encryption key for basic encryption, 112-bitkey for moderate encryption, and a 168-bit encryption key (3DES) for strong encryption. It also allowsthe Advanced Encryption Standard (AES), a block data encryption method, using 128-bit, 192-bit, or256-bit encryption.WatchGuard also has an separate SSL VPN Firebox product line. You can see more information on theWatchGuard public web site at http://www.watchguard.com/products/fb-ssl.asp.Remote User VPN with PPTPRemote User VPN allows remote users or mobile users to connect to the Firebox® network with PPTP.RUVPN with PPTP allows RC4 40-bit or 128-bit keys.The basic WatchGuard System Manager package includes RUVPN with PPTP. It allows 50 users, and alllevels of encryption. For information on how to create RUVPN with PPTP tunnels, see the “ConfiguringRUVPN with PPTP” chapter.Mobile User VPNNoteFor information on how to configure and use MUVPN, see the MUVPN Administrator Guide.Mobile User VPN is an optional software component available for all Firebox models. Remote users aremobile employees who must have corporate network access. MUVPN creates an IPSec tunnel between aremote host that is not secure and your corporate network. Remote users connect to the Internet with astandard Internet dial-up or broadband connection, and then they use the MUVPN software to make asecure connection to the network or networks protected by the Firebox. With MUVPN, only one Fireboxis necessary to create the tunnel.MUVPN uses IPSec with DES or 3DES to encrypt incoming traffic, and MD5 or SHA-1 to authenticate datapackets. You configure a security policy and supply it along with the MUVPN software to each remoteuser. The security policy is an encrypted file with the extension wgx. When the software is installed onthe computers of the remote users, they can safely connect to the corporate network. MUVPN users canchange their security policies, or you can give them read-only security policies.232 WatchGuard System Manager

WatchGuard VPN SolutionsBranch Office Virtual Private Network (BOVPN)Many companies have offices in more than one location. Offices frequently use data from other locations,or have access to shared databases.Because branch offices have sensitive company data, information interchanges must be secure. Whenyou use WatchGuard Branch Office VPN, you can connect two or more locations across the Internetwithout decreasing security. WatchGuard BOVPN supplies an encrypted tunnel between two networksor between a Firebox and an IPSec-compliant device. You can use WatchGuard System Manager or PolicyManager to configure BOVPN.WatchGuard allows certificate-based authentication for BOVPN tunnels. When you use certificate-basedauthentication for BOVPN, the two VPN endpoints must be WatchGuard Fireboxes. You cannot use certificate-basedauthentication for BOVPN with SOHO 6 or Firebox X Edge devices. To use this functionality,you must configure a Management Server and a certificate authority. For more information, see“Configuring Managed VPN Tunnels,” on page 237. For instructions on how to use Policy Manager tomanually configure a BOVPN tunnel, see “Configuring BOVPN with Manual IPSec,” on page 243.BOVPN with Policy ManagerWhen you make a tunnel with Policy Manager, the Firebox uses IPSec to make encrypted tunnels with adifferent IPSec-compliant security device. One of the two endpoints must have a public static IP address.Use BOVPN with Policy Manager if:• You make tunnels between a Firebox and a non-WatchGuard, IPSec-compliant unit.• You give different routing policies to different tunnels.• Not all types of traffic go through the tunnel.BOVPN with IPSec is available with the moderate encryption level of DES (56-bit), or the strongerencryption 3DES (168-bit). BOVPN is also available with AES at the 128-bit, 192-bit, and 256-bit encryptionlevels. AES with 256-bit encryption is the most secure.You can create different VPN tunnels for different types of traffic on your network. For example, you canuse a VPN tunnel with DES encryption for traffic from your sales team. At the same time use a VPN tunnelwith stronger, 3DES encryption for all data from your finance department.BOVPN with Manual IPSecBOVPN with WatchGuard System ManagerWith WatchGuard System Manager, you can make fully authenticated and encrypted IPSec tunnels witha drag-and-drop or menu interface. WatchGuard System Manager uses the Management Server tosafely transmit IPSec VPN configuration information between two Firebox devices. When you use theManagement Server, you set each configuration parameter of the VPN. The Management Server keepsthis information.Use BOVPN with WatchGuard System Manager if:User Guide 233

<strong>WatchGuard</strong> VPN SolutionsBranch Office Virtual Private Network (BOVPN)Many companies have offices in more than one location. Offices frequently use data from other locations,or have access to shared databases.Because branch offices have sensitive company data, information interchanges must be secure. Whenyou use <strong>WatchGuard</strong> Branch Office VPN, you can connect two or more locations across the Internetwithout decreasing security. <strong>WatchGuard</strong> BOVPN supplies an encrypted tunnel between two networksor between a Firebox and an IPSec-compliant device. You can use <strong>WatchGuard</strong> System Manager or PolicyManager to configure BOVPN.<strong>WatchGuard</strong> allows certificate-based authentication for BOVPN tunnels. When you use certificate-basedauthentication for BOVPN, the two VPN endpoints must be <strong>WatchGuard</strong> Fireboxes. You cannot use certificate-basedauthentication for BOVPN with SOHO 6 or Firebox X Edge devices. To use this functionality,you must configure a Management Server and a certificate authority. For more information, see“Configuring Managed VPN Tunnels,” on page 237. For instructions on how to use Policy Manager tomanually configure a BOVPN tunnel, see “Configuring BOVPN with Manual IPSec,” on page 243.BOVPN with Policy ManagerWhen you make a tunnel with Policy Manager, the Firebox uses IPSec to make encrypted tunnels with adifferent IPSec-compliant security device. One of the two endpoints must have a public static IP address.Use BOVPN with Policy Manager if:• You make tunnels between a Firebox and a non-<strong>WatchGuard</strong>, IPSec-compliant unit.• You give different routing policies to different tunnels.• Not all types of traffic go through the tunnel.BOVPN with IPSec is available with the moderate encryption level of DES (56-bit), or the strongerencryption 3DES (168-bit). BOVPN is also available with AES at the 128-bit, 192-bit, and 256-bit encryptionlevels. AES with 256-bit encryption is the most secure.You can create different VPN tunnels for different types of traffic on your network. For example, you canuse a VPN tunnel with DES encryption for traffic from your sales team. At the same time use a VPN tunnelwith stronger, 3DES encryption for all data from your finance department.BOVPN with Manual IPSecBOVPN with <strong>WatchGuard</strong> System ManagerWith <strong>WatchGuard</strong> System Manager, you can make fully authenticated and encrypted IPSec tunnels witha drag-and-drop or menu interface. <strong>WatchGuard</strong> System Manager uses the Management Server tosafely transmit IPSec VPN configuration information between two Firebox devices. When you use theManagement Server, you set each configuration parameter of the VPN. The Management Server keepsthis information.Use BOVPN with <strong>WatchGuard</strong> System Manager if:<strong>User</strong> <strong>Guide</strong> 233

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!