NETGEAR SSL312 manual Users, Groups and Global Policies

Page 48

NETGEAR ProSafe SSL VPN Concentrator 25 SSL312 Reference Manual

To create complex policies involving groups of host names, IP addresses or IP address ranges, you can define these groups as network objects using Network Resources as described in “Using Network Resource Objects to Simplify Policies” on page 4-20.

To present different portal content to different users (for example, external suppliers), create the new portal layout, then add a new domain, selecting the new portal layout.

Users, Groups and Global Policies

An administrator can define and apply user, group and global policies to predefined network resource objects, IP addresses, address ranges, or all IP addresses and to different SSL VPN services. A specific hierarchy is invoked over which policies take precedence. The SSL VPN Concentrator policy hierarchy is defined as:

1.User Policies take precedence over all Group Policies.

2.Group Policies take precedence over all Global Policies.

3.If two or more user, group or global policies are configured, the most specific policy takes precedence.

For example, a policy configured for a single IP address takes precedence over a policy configured for a range of addresses. And a policy that applies to a range of IP addresses takes precedence over a policy applied to all IP addresses. If two or more IP address ranges are configured, then the smallest address range takes precedence. Hostnames are treated the same as individual IP addresses.

Network Resources are prioritized just like other address ranges. However, the prioritization is based on the individual address or address range, not the entire Network Resource.

For example, let’s assume the following global policy configuration:

Policy 1: A Deny rule has been configured to block all services to the IP address range

10.0.0.0– 10.0.0.255.

Policy 2: A Deny rule has been configured to block FTP access to 10.0.1.2 – 10.0.1.10.

Policy 3: A Permit rule has been configured to allow FTP access to the predefined network resource, FTP Servers. The FTP Servers network resource includes the following addresses:

10.0.0.5– 10.0.0.20 and ftp.company.com, which resolves to 10.0.1.3.

Assuming that no conflicting user or group policies have been configured, if a user attempted to access:

An FTP server at 10.0.0.1, the user would be blocked by Policy 1.

4-2

Setting Up User and Group Access Policies

v2.0, May 2007

Image 48
Contents Netgear ProSafe SSL VPN Concentrator SSL312 Reference Manual Technical Support Licensing Product and Publication Details Contents Chapter Authenticating Users Chapter Configuring the Remote Access Web Portal Chapter Monitoring and Logging About This Manual Conventions, Formats and ScopeUsing This Manual Printing this ManualPrinting a Chapter Revision History Version Date Description of ChangesKey Features Chapter IntroductionAbout the ProSafe SSL VPN Concentrator Web Browser Requirements Microsoft WindowsWhat’s in the Box Hardware DescriptionFront Panel Back Panel Steps for Deploying the SSL312 V2.0, May Chapter Installing the SSL312 Choosing a Network TopologySingle Arm Routing Initial Connection to the SSL VPN Concentrator Accessing the Management Interface Https//192.168.1.1V2.0, May Configuring Basic Network Settings V2.0, May Installing the SSL VPN Concentrator Managing CertificatesObtaining a Certificate from a Certificate Authority Generating a Self-Signed Certificate Uploading and Enabling the New Certificate V2.0, May Viewing and Deleting Certificates Steps for Further Configuration Chapter Authenticating Users Authentication DomainsLocal User Database Authentication Radius and NT Domain Authentication Configuring for Radius Domain Authentication Configuring for NT Domain Authentication Ldap Authentication Sample Ldap Attributes Ldap Attribute RulesSample Ldap Users and Attributes Settings Querying an Ldap ServerConfiguring for Ldap Authentication CN=Users,DC=yourdomain,DC=comActive Directory Authentication Configuring for Windows Active Directory AuthenticationV2.0, May Kerberos Authentication Troubleshooting Active Directory AuthenticationDeleting a Domain Https//IP/Domain Name/portal/Portal NameV2.0, May Setting Up User and Group Access Policies Determine Your RequirementsUsers, Groups and Global Policies Global Policies Editing Global Policy Settings Adding and Editing Global Policies Defining and Editing Global Bookmarks Groups Configuration Adding a New GroupEditing Group Settings Defining and Editing Group Policies V2.0, May Defining and Editing Group Bookmarks Deleting a Group Users Configuration Adding a New User V2.0, May Editing a User V2.0, May Defining and Editing User Policies Defining and Editing a User Bookmarks Using Network Resource Objects to Simplify Policies Deleting a UserV2.0, May V2.0, May V2.0, May V2.0, May Configuring the Remote Access Web Portal Portal LayoutsPortal Option Features for Remote Users Portal OptionsAdding Portal Layouts V2.0, May V2.0, May Adding Terminal Services Applications to the Portal Customizing the Banner Duplicating and Editing Portal Layouts Creating a Guide to Using the Portal V2.0, May Two Approaches for VPN SSL VPN Client Configuration Adding IP Address Ranges Adding Routes for VPN Tunnel Clients V2.0, May Configuring Applications for Port Forwarding Port Forwarding Applications/TCP Port Numbers Configuring Host Name Resolution SSHChapter Additional System Configuration Configuring Network SettingsSample SSL VPN Concentrator Configuration Network Interface and Default Gateway Configuration Default gateway address Firewall/Router addressV2.0, May Static Route Configuration V2.0, May Network Host Table Settings Configuring DNS Settings V2.0, May Setting Date and Time System Configuration Utilities Encrypting the Configuration File Exporting and Saving a Backup Configuration FileImporting a Configuration File Erasing the Configuration and Restoring the Default Settings Upgrading the SSL VPN Concentrator FirmwareAdditional Notes on the Management Interface Chapter Monitoring and Logging SSL VPN Concentrator StatusMonitoring and Logging Active Users Event Log Log Settings Send Logs Weekly Schedule Send Logs Daily Schedule V2.0, May V2.0, May Diagnostics V2.0, May Appendix a Default Settings and Technical Specifications Factory Default SettingsTechnical Specifications GMTAppendix B Related Documents Document LinkV2.0, May Index NumericsIndex-2 Index-3 Index-4 Index-5 Index-6
Related manuals
Manual 112 pages 5.2 Kb