13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring services to allow incoming RUVPN4 To add the user to a group, select the group name in the Not Member Of list. Clickthe left-pointing arrow.Use pptp_users for Remote <strong>User</strong> PPTP and ipsec_users for Mobile <strong>User</strong> VPN. A given user canbe a member of both groups.5 When you finish adding the user to groups, click Add.The user is added to the <strong>User</strong>s list. The Setup Remote <strong>User</strong> dialog box remains open and clearedso you can add another user.6 Click Close to close the Setup Remote <strong>User</strong> dialog box.The <strong>Firebox</strong> <strong>User</strong>s tab appears with a list of the newly configured user(s).Configuring services to allow incoming RUVPNUse the <strong>Firebox</strong> user groups (pptp_users and ipsec_users) to quickly configure theallowed services for incoming RUVPN traffic. There are two recommended methods:By individual serviceDouble-click each service that you want to enable for your remote VPN users. Set thefollowing properties on the service:Enable permissions for pptp_users if you are configuring Remote <strong>User</strong> PPTP.Enable permissions for ipsec_users if you are configuring Mobile <strong>User</strong> VPN.Incoming- Enabled and allowed- From: pptp_users or ipsec_users- To: Any (or selected)Outgoing- Outgoing allowed- From: Any (or selected)- To: pptp_users or ipsec_usersUsing the Any serviceAdd the Any service with the following properties:Incoming- Enabled and allowed- From: pptp_users or ipsec_users- To: SelectedOutgoing- Enabled and allowed- From: Selected- To: pptp_users or ipsec_users<strong>User</strong> <strong>Guide</strong> 135

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!