13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring shared servers for RUVPN• The IP addresses of the DNS and WINS servers in the trusted network thatperform IP address lookup on host alias names.• The usernames and passwords of those authorized to connect to the <strong>Firebox</strong> usingRUVPN.• For Mobile <strong>User</strong> VPN, you will also need:- Mobile <strong>User</strong> VPN license key- Target <strong>Firebox</strong> upgraded to strong or medium encryptionConfiguring shared servers for RUVPNRUVPN clients rely on shared Windows Internet Name Server (WINS) and DomainName <strong>System</strong> (DNS) server addresses. For information on configuring these servers,see “Entering WINS and DNS server addresses” on page 39.Adding remote access usersThe <strong>Firebox</strong> configuration file automatically includes two <strong>Firebox</strong> <strong>User</strong> groups calledpptp_users and ipsec_users. When a remote host connects and creates a tunnel,Policy Manager authenticates the username against the list of members for the groupassociated with the tunnel type. In other words, an incoming PPTP tunnel wouldauthenticate against the pptp_users group.Once authenticated, the Policy Manager then adds the remote client IP address to thegroup. Use the <strong>Firebox</strong> <strong>User</strong> group to configure services for incoming and outgoingRUVPN traffic.Because of the way Windows holds the username and password for subsequentlogins, one option to reduce end-user confusion is to assign the same RUVPN loginand password as those used for Windows NT login and password. This method,however, is less secure than using multiple passwords.RUVPN users must be added as <strong>Firebox</strong> users even if another authenticationmethod is used internally.Adding a member to built-in RUVPN user groupsThe process to add a member to the built-in RUVPN user groups is the same for bothPPTP and IPSec. The example below is for pptp_users. From Policy Manager:1 Select Setup => Authentication.2 Click the <strong>Firebox</strong> <strong>User</strong>s tab. To add a new user, click the Add button beneath the<strong>User</strong>s list.There is also a button to access the Setup <strong>Firebox</strong> <strong>User</strong> dialog box from within the Mobile <strong>User</strong>VPN wizard.3 Enter the username and password.<strong>Firebox</strong> usernames are case sensitive.134

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!