Netgear FVS336G FVS336G Reference Manual - Page 130

Planning for SSL VPN, Port Forwarding

Page 130 highlights

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual firewall. Upon successful connection, an ActiveX-based SSL VPN client is downloaded to the remote PC that will allow the remote user to virtually join the corporate network. The SSL VPN Client provides a PPP (point-to-point) connection between the client and the VPN firewall, and a virtual network interface is created on the user's PC. The VPN firewall will assign the PC an IP address and DNS server IP addresses, allowing the remote PC to access network resources in the same manner as if it were connected directly to the corporate network, subject to any policy restrictions configured by the administrator. • Port Forwarding Like VPN Tunnel, Port Forwarding is a web-based client that installs transparently and then creates a virtual, encrypted tunnel to the remote network. However, Port Forwarding differs from VPN Tunnel in several ways. For example, Port Forwarding: - Only supports TCP connections, not UDP or other IP protocols. - Detects and reroutes individual data streams on the user's PC to the Port Forwarding connection rather than opening up a full tunnel to the corporate network. - Offers more fine grained management than VPN Tunnel. The administrator defines individual applications and resources that will be available to remote users. The SSL VPN portal can present the remote user with one or both of these SSL service levels, depending on the configuration by the administrator. Planning for SSL VPN To set up and activate SSL VPN connections, you will perform these basic steps in this order: 1. Edit the existing SSL Portal or create a new one. When remote users log in to the SSL VPN firewall, they see a portal page that you can customize to present the resources and functions that you choose to make available. 2. Create one or more authentication domains for authentication of SSL VPN users. When remote users log in to the SSL VPN firewall, they must specify a domain to which their login account belongs. The domain determines the authentication method to be used and the portal layout that will be presented, which in turn determines the network resources to which they will have access. Because you must assign a portal layout when creating a domain, the domain is created after you have created the portal layout. 3. Create one or more groups for your SSL VPN users. 6-2 Virtual Private Networking Using SSL Connections v1.2, June 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual
6-2
Virtual Private Networking Using SSL Connections
v1.2, June 2008
firewall. Upon successful connection, an ActiveX-based SSL VPN client is downloaded to the
remote PC that will allow the remote user to virtually join the corporate network. The SSL
VPN Client provides a PPP (point-to-point) connection between the client and the VPN
firewall, and a virtual network interface is created on the user’s PC. The VPN firewall will
assign the PC an IP address and DNS server IP addresses, allowing the remote PC to access
network resources in the same manner as if it were connected directly to the corporate
network, subject to any policy restrictions configured by the administrator.
Port Forwarding
Like VPN Tunnel, Port Forwarding is a web-based client that installs transparently and then
creates a virtual, encrypted tunnel to the remote network. However, Port Forwarding differs
from VPN Tunnel in several ways. For example, Port Forwarding:
Only supports TCP connections, not UDP or other IP protocols.
Detects and reroutes individual data streams on the user’s PC to the Port Forwarding
connection rather than opening up a full tunnel to the corporate network.
Offers more fine grained management than VPN Tunnel. The administrator defines
individual applications and resources that will be available to remote users.
The SSL VPN portal can present the remote user with one or both of these SSL service levels,
depending on the configuration by the administrator.
Planning for SSL VPN
To set up and activate SSL VPN connections, you will perform these basic steps in this order:
1.
Edit the existing SSL Portal or create a new one.
When remote users log in to the SSL VPN firewall, they see a portal page that you can
customize to present the resources and functions that you choose to make available.
2.
Create one or more authentication domains for authentication of SSL VPN users.
When remote users log in to the SSL VPN firewall, they must specify a domain to which their
login account belongs. The domain determines the authentication method to be used and the
portal layout that will be presented, which in turn determines the network resources to which
they will have access. Because you must assign a portal layout when creating a domain, the
domain is created after you have created the portal layout.
3.
Create one or more groups for your SSL VPN users.