13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the <strong>Firebox</strong> for Mobile <strong>User</strong> VPN3 Use the Choose Type drop list to select either a host or network.You can configure up to 50 addresses. If you select a network address, Remote <strong>User</strong> PPTP willuse the first 50 addresses in the subnet.4 In the Value field, enter the host or network address in slash notation. Click OK.Enter unused IP addresses that the <strong>Firebox</strong> can dynamically assign to clients during Remote <strong>User</strong>PPTP sessions. Selected addresses must not appear in the Blocked Sites list. The IP addressappears in the list of addresses available to remote clients.5 Repeat the add process until you have configured all addresses for use withRemote <strong>User</strong> PPTP.Rules for valid Remote <strong>User</strong> PPTP addresses• Addresses that have host routes are invalid• Traffic routed through the default gateway does not receive proxy ARP treatment• Addresses whose packets would be routed through the External interface (but notthrough the default gateway) are invalid• Addresses in networks to which you have routes are invalid (except those that arerouted through default route)• Any other packets are allowed and handled by proxy ARPConfiguring the <strong>Firebox</strong> for Mobile <strong>User</strong> VPNMobile <strong>User</strong> VPN requires careful configuration of both the <strong>Firebox</strong> and the remoteclient computers. However, unlike Remote <strong>User</strong> PPTP, the <strong>Firebox</strong> administratorretains more control over the client configuration through an end-user configurationfile. Configuring the <strong>Firebox</strong> for Mobile <strong>User</strong> VPN requires the following steps:• Obtain a license key from <strong>WatchGuard</strong>• Add user names to the built-in <strong>Firebox</strong> group ipsec_users• Enter the IPSec license key into the <strong>Firebox</strong> configuration file• Verify WINS and DNS server settings• Use Policy Manager to simultaneously configure the <strong>Firebox</strong> and create end-userconfiguration files• Configure service properties using ipsec_users• Distribute the end-user configuration files along with the RUVPN client softwareand documentationPurchasing a Mobile <strong>User</strong> VPN license<strong>WatchGuard</strong> Mobile <strong>User</strong> VPN is an optional feature of the <strong>WatchGuard</strong> <strong>Firebox</strong><strong>System</strong>. Although the administrative tools to configure Mobile <strong>User</strong> VPN areautomatically included in the Policy Manager software, to activate the feature alicense for each installation of the client software must be purchased. To purchaseIPSec license keys, contact your local reseller or visit:http://www.watchguard.com/sales<strong>User</strong> <strong>Guide</strong> 137

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!