WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

Using Remote User PPTPInstalling a VPN adapter on Windows NTFrom the Windows NT Desktop of the remote host:1 Double-click My Computer.2 Double-click Dial-Up Networking.If you have not already configured an entry, Windows guides you through the creation of a dial-upconfiguration. When it prompts for a phone number, enter the host name or IP address of theFirebox. When complete, you should see a Dial-Up Networking dialog box with the default buttonDial.3 Select New to make a new connection. If you are prompted to use the wizard,enter a friendly connection name and enable the I Know All About checkbox.The connection name used in the WatchGuard client brochures included on the WatchGuard NOCSecurity Suite installation CD-ROM is “Connect to RUVPN.”4 Under the Basic tab, configure the following settings:- Phone Number: Firebox IP address- Entry Name: Connect to RUVPN (or your preferred alternative)- Dial Using: RASPPTPM (VPN1) adapter- Use Another Port if Busy: enabled5 Click the Server tab. Configure the following settings:- PPP: Windows NT, Windows 95 Plus, Internet- TCP/IP: enabled- Enable Software Compression: enabled6 Click the Security tab. Configure the following settings:- Accept Only Microsoft Encrypted Authentication: enabled- Require Data Encryption: enabled7 Click OK.Using Remote User PPTPUsing Remote User PPTP is a two-step process. First, the remote host establishes aconnection to the ISP. It then uses the VPN adapter to create a PPTP tunnel to theFirebox.Starting Remote User PPTPThe connect process is identical regardless of the Windows platform. From theWindows Desktop:1 Establish an Internet connection through either Dial-Up Networking or directlythrough a LAN or WAN.2 Double-click My Computer. Double-click Dial-Up Networking.3 Double-click the RUVPN connection.If you configured the client computer as described in “Windows 95/98 platform preparation” onpage 142, double-click Connect with RUVPN.146

Configuring debugging options4 Enter the remote client username and password.These are assigned when you add the user to the pptp_users group. See “Using Remote UserPPTP” on page 146.5 Click Connect.Running Remote User PPTPWhen first starting the remote host (before connecting to the ISP or to the Firebox),the user may be prompted for a name, password, and possibly even a domain. Thesevalues are what Windows assumes the remote host uses to connect to the networkbehind the Firebox. However, if Windows finds a discrepancy, it displays a loginprompt for the network with the name, password, and domain that would be used ifthe remote host were at an office connecting directly to the LAN.Remote User PPTP is usually set up such that the remote machines usenonpublic IP addresses from the range used behind a Firebox. If the “UseDefault Gateway on Remote Network” parameter is enabled, and you try tobrowse the Internet during a Remote User PPTP session, the Fireboxtransmits the private address as the source IP address in the packetheader. Because the remote host was assigned an address from a privateaddress pool, a public Web site will not know how to route the returntraffic, and will ignore your request. Therefore, browse the Internet beforeor after you are connected to the Firebox, but not during a Remote UserPPTP session.If simultaneous access to the Internet and a private network is required,contact WatchGuard Support for alternative solutions.Configuring debugging optionsWatchGuard offers a selection of debugging options that you can set to gatherinformation and help with future troubleshooting.For information on how to enable logging for IPSec, see “Debugging Mobile UserVPN” on page 140. For information on how to enable logging for PPTP, see“Debugging Remote User VPN (PPTP)” on page 140.User Guide 147

Using Remote <strong>User</strong> PPTPInstalling a VPN adapter on Windows NTFrom the Windows NT Desktop of the remote host:1 Double-click My Computer.2 Double-click Dial-Up Networking.If you have not already configured an entry, Windows guides you through the creation of a dial-upconfiguration. When it prompts for a phone number, enter the host name or IP address of the<strong>Firebox</strong>. When complete, you should see a Dial-Up Networking dialog box with the default buttonDial.3 Select New to make a new connection. If you are prompted to use the wizard,enter a friendly connection name and enable the I Know All About checkbox.The connection name used in the <strong>WatchGuard</strong> client brochures included on the <strong>WatchGuard</strong> NOCSecurity Suite installation CD-ROM is “Connect to RUVPN.”4 Under the Basic tab, configure the following settings:- Phone Number: <strong>Firebox</strong> IP address- Entry Name: Connect to RUVPN (or your preferred alternative)- Dial Using: RASPPTPM (VPN1) adapter- Use Another Port if Busy: enabled5 Click the Server tab. Configure the following settings:- PPP: Windows NT, Windows 95 Plus, Internet- TCP/IP: enabled- Enable Software Compression: enabled6 Click the Security tab. Configure the following settings:- Accept Only Microsoft Encrypted Authentication: enabled- Require Data Encryption: enabled7 Click OK.Using Remote <strong>User</strong> PPTPUsing Remote <strong>User</strong> PPTP is a two-step process. First, the remote host establishes aconnection to the ISP. It then uses the VPN adapter to create a PPTP tunnel to the<strong>Firebox</strong>.Starting Remote <strong>User</strong> PPTPThe connect process is identical regardless of the Windows platform. From theWindows Desktop:1 Establish an Internet connection through either Dial-Up Networking or directlythrough a LAN or WAN.2 Double-click My Computer. Double-click Dial-Up Networking.3 Double-click the RUVPN connection.If you configured the client computer as described in “Windows 95/98 platform preparation” onpage 142, double-click Connect with RUVPN.146

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!