WatchGuard Technologies V10.0 manual Modifying an Existing Mobile VPN Profile

Page 14

Modifying an Existing Mobile VPN Profile

Adding Users to a Firebox Mobile VPN Group

To create an Mobile VPN tunnel with the Firebox, remote users type their user name and password to authenticate. WatchGuard® System Manager software uses this information to authenticate the user to the Firebox®.

To authenticate, users must be part of the group entered in the Add Mobile User VPN Wizard. If you use Firebox authentication, use the instructions below. If you use a third-party authentication server, use the instructions provided in your vendor documentation. For more information on Firebox groups, see the Authentication chapter in the WatchGuard System Manager User Guide.

1From Policy Manager, select Setup > Authentication > Authentication Servers.

The Authentication Servers dialog box appears.

2Make sure that the Firebox tab is selected.

3To add a new user, click the Add button below the Users list.

The Setup Firebox User dialog box appears.

4Type a user name and passphrase for the new user. Type the passphrase again to confirm it.

Description is not required. Do not change the values for Session Timeout and Idle Timeout unless the change is necessary.

5In the Firebox Authentication Groups area use the horizontal arrows to make the new user a member of the group you created in the wizard.

6Click OK.

The new user appears in the Users list in the Authentication Servers dialog box. The dialog box stays open for you to add more users if you choose.

7To close the Authentication Servers dialog box, click OK.

Modifying an Existing Mobile VPN Profile

After you use the Mobile User VPN wizard to create a new .wgx file, you can make changes to the profile to:

Change the shared key

Add access to more hosts or networks

Restrict access to a single destination port, source port, or protocol

Change the Phase 1 or Phase 2 settings.

1From Policy Manager, select VPN > Remote Users.

2From the list of user names and groups on the Remote User VPN dialog box, click the user name or group to change.

12

Mobile User VPN

Image 14
Contents WatchGuardMobile VPN with IPSec Administrator Guide Address About Mobile VPN Client Configuration Files Before You BeginSelect the Enable Muvpn for this account check box Enabling Mobile VPN for a Firebox User AccountConfiguring Global Mobile VPN Client Settings Get the user’s .wgx fileDistributing the Software and Profiles Distributing the Software and ProfilesEnd-user profile Distributing the Software and Profiles Mobile User VPN Before You Begin Configuring the Firebox for Mobile VPN Select a user authentication server Configuring the Firebox for Mobile VPN Configuring the external authentication server Modifying an Existing Mobile VPN Profile Adding Users to a Firebox Mobile VPN GroupConfirm Use a certificate Phase2 Settings Defining advanced Phase 1 settings Configuring Wins and DNS Servers Allowing Internet access through Mobile VPN tunnelsLocking Down an End-User Profile On the Mobile User VPN tab, click AdvancedSeeing details on an Mobile VPN policy Configuring Policies to Filter Mobile VPN TrafficAdd individual policies Saving the Profile to a Firebox Using the Any PolicyRe-creating End-User Profiles Additional Mobile VPN Topics Making outbound IPSec connections from behind a FireboxTerminating IPSec connections Global VPN settingsAdding feature keys Seeing the number of Mobile VPN licensesMobile VPN Client Installation and Connection Installing the Mobile VPN with IPSec Client Window AutoStart No Autostart Select Configuration Profile ImportImporting the end-user profile Selecting a certificate and entering the PIN Connecting the Mobile VPN ClientUninstalling the Mobile VPN client Start All Programs WatchGuard Mobile VPN Mobile VPN Monitor Disconnecting the Mobile VPN clientControlling connection behavior Seeing Mobile VPN Log Messages Mobile User VPN client iconSecuring Your Computer with the Mobile VPN Firewall Enabling the link firewallEnabling the desktop firewall Configuration Firewall SettingsAbout the desktop firewall Defining friendly networks Creating firewall rulesGeneral tab Local tab Remote tab