12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CHAPTER 22Configuring RUVPN with PPTPRemote <strong>User</strong> Virtual Private Networking (RUVPN) uses Point-to-Point Tunneling Protocol (PPTP) to makea secure connection. It supports as many as 50 users at the same time for each Firebox®. RUVPN userscan authenticate to the Firebox or to a RADIUS authentication server. You must configure the Fireboxand the remote host computers of the remote user.Configuration ChecklistBefore you configure a Firebox® to use RUVPN, record this information:• The IP addresses for the remote client to use for RUVPN sessions. These IP addresses cannot beaddresses that the network behind the Firebox uses. The safest procedure to give addressesfor RUVPN users is to install a “placeholder” secondary network with a range of IP addresses.Then, select an IP address from that network range. For example, create a new subnet as asecondary network on your trusted network 10.10.0.0/24. Select the IP addresses in this subnetfor your range of PPTP addresses. For more information, see “IP Addressing” on page 228.• The IP addresses of the DNS and WINS servers that resolve host names to IP addresses.• The user names and passphrases of users that are allowed to connect to the Firebox with RUVPN.Encryption levelsFor RUVPN with PPTP, you can select to use 128-bit encryption or 40-bit encryption. U.S. domestic versionsof Windows XP have 128-bit encryption enabled. You can get a strong encryption patch fromMicrosoft for other versions of Windows. The Firebox always tries to use 128-bit encryption first. It uses40-bit encryption (if enabled) if the client cannot use the 128-bit encrypted connection.For information on how to enable the drop from 128-bit to 40-bit, see “Preparing the Client Computers”on page 284.If you do not live in the U.S. and you must have strong encryption allowed on your LiveSecurity Serviceaccount, send an e-mail to supportid@watchguard.com and include in it:• Your LiveSecurity Service key number• Date of purchase• Name of your company<strong>User</strong> <strong>Guide</strong> 279

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!