12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Packet Filter PoliciesPPTPPPTP is a VPN tunnel protocol with encryption. It uses one TCP port (for negotiation and authenticationof a VPN connection) and one IP protocol (for data transfer) to connect the two peers in a VPN. Configurethe PPTP policy to allow access from Internet hosts to an internal network PPTP server. PPTP cannotget access to hosts’ static NAT because NAT cannot forward IP protocols. Because this policy enables atunnel to the PPTP server and the Firebox cannot examine packets in the tunnel, use of this policy mustbe controlled. Be sure to use the most current version of PPTP.Characteristics• Internet Protocol(s): TCP• PPTP Negotiation Port Number(s): 1723RADIUS and RADIUS-RFCThe Remote Authentication Dial-In <strong>User</strong> Service (RADIUS) supplies remote users with secure access tocorporate networks. RADIUS is a client-server system that keeps authentication information for users,remote access servers, and VPN gateways in a central user database that is available to all servers.Authentication for the network occurs from one location. RADIUS uses an authentication key that identifiesan authentication request to the RADIUS client.In RFC 2865, the server port used by RADIUS changed from port 1645 to 1812. Make sure you select thepolicy that matches your implementation.Characteristics• Internet Protocol(s): UDP• RADIUS policy Port Number(s): UDP 1645• RADIUS-RFC policy Port Number(s): UDP 1812RADIUS-Accounting and RADIUS-ACCT-RFCThe Remote Authentication Dial-In <strong>User</strong> Service (RADIUS) Accounting policy supplies accounting informationto administrators of networks that use RADIUS authentication. RADIUS is a client-server systemthat keeps authentication information for users, remote access servers, and VPN gateways in a centraluser database that is available to all servers. The RADIUS server is also notified when the authenticatedsession starts and stops. This information can be helpful for accounting.In RFC 2866, the server port used by RADIUS changed from port 1646 to 1813. Make sure you select thepolicy that matches your implementation.Characteristics• Internet Protocol(s): TCP• RADIUS-Accounting policy Port Number(s): UDP1646• RADIUS-ACCT-RFC policy Port Number(s): UDP 1813RDPThe Microsoft Remote Desktop Protocol (RDP) supplies remote display and input abilities over networkconnections for Windows software applications that operate on a server.390 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!