WatchGuard Technologies V10.0 manual About Mobile VPN Client Configuration Files

Page 10

About Mobile VPN Client Configuration Files

About Mobile VPN Client Configuration Files

With Mobile VPN with IPSec, the network security administrator controls end-user profiles. Policy Man- ager is used to set the name of the end user and create a client configuration file, or profile, with the file extension .wgx. The .wgx file contains the shared key, user identification, IP addresses, and settings that are used to create a secure tunnel between the remote computer and the Firebox®. This file is encrypted with a key that is eight characters or greater in length. This key must be known to the administrator and the remote user. When the .wgx file is imported on the remote client, this key is used to decrypt the file for the client software to use.

After you use the Add Mobile User VPN wizard, you can create or re-create a .wgx file at any time.

If you want to lock the profiles for mobile users by making them read-only, see “Locking Down an End- User Profile” on page 18.

Configuring the Firebox for Mobile VPN

Use this procedure to enable Mobile VPN for an existing group of users or a new group you want to cre- ate. The users that are part of the group can authenticate to the local Firebox® authentication server, or to a third-party authentication server configured in your Firebox configuration. If you use Firebox authentication, use the instructions in “Adding Users to a Firebox Mobile VPN Group” on page 12 to add users to your group. If you use a third-party authentication server, use the instructions provided in that vendor’s documentation.

1From Policy Manager, select VPN > Remote Users.

The Remote User VPN configuration dialog box appears.

2Click Add.

The Add Mobile User VPN Wizard appears.

8

Mobile User VPN

Image 10
Contents WatchGuardMobile VPN with IPSec Administrator Guide Address About Mobile VPN Client Configuration Files Before You BeginSelect the Enable Muvpn for this account check box Enabling Mobile VPN for a Firebox User AccountConfiguring Global Mobile VPN Client Settings Get the user’s .wgx fileDistributing the Software and Profiles Distributing the Software and ProfilesEnd-user profile Distributing the Software and Profiles Mobile User VPN Before You Begin Configuring the Firebox for Mobile VPN Select a user authentication server Configuring the Firebox for Mobile VPN Configuring the external authentication server Modifying an Existing Mobile VPN Profile Adding Users to a Firebox Mobile VPN GroupConfirm Use a certificate Phase2 Settings Defining advanced Phase 1 settings Configuring Wins and DNS Servers Allowing Internet access through Mobile VPN tunnelsLocking Down an End-User Profile On the Mobile User VPN tab, click AdvancedAdd individual policies Configuring Policies to Filter Mobile VPN TrafficSeeing details on an Mobile VPN policy Re-creating End-User Profiles Using the Any PolicySaving the Profile to a Firebox Additional Mobile VPN Topics Making outbound IPSec connections from behind a FireboxTerminating IPSec connections Global VPN settingsAdding feature keys Seeing the number of Mobile VPN licensesMobile VPN Client Installation and Connection Installing the Mobile VPN with IPSec Client Importing the end-user profile Select Configuration Profile ImportWindow AutoStart No Autostart Uninstalling the Mobile VPN client Connecting the Mobile VPN ClientSelecting a certificate and entering the PIN Controlling connection behavior Disconnecting the Mobile VPN clientStart All Programs WatchGuard Mobile VPN Mobile VPN Monitor Seeing Mobile VPN Log Messages Mobile User VPN client iconSecuring Your Computer with the Mobile VPN Firewall Enabling the link firewallAbout the desktop firewall Configuration Firewall SettingsEnabling the desktop firewall Defining friendly networks Creating firewall rulesGeneral tab Local tab Remote tab