WatchGuard Technologies V10.0 manual Configuring Global Mobile VPN Client Settings

Page 5

Configuring Global Mobile VPN Client Settings

10Set MUVPN key expiration in kilobytes and/or hours. The default values are 8192 KB and 24 hours.

To remove a size and/or time expiration, set the value to zero (0).

11Make sure the VPN Client Type drop-down list is set to Mobile User. This is true whether you use a Windows desktop, laptop, or handheld PC.

12Select the All traffic uses tunnel (0.0.0.0/0 IP Subnet) check box if the remote client sends all its traffic (including usual web traffic) through the VPN tunnel to the Firebox X Edge. This can also let the Mobile VPN client connect with other networks that the Edge connects to.

If you do not select this check box, the remote user can connect with the Firebox X Edge trusted network only. You must select this check box for the remote user to be able to connect to:

-Networks on the other side of a Branch Office VPN tunnel that the Edge has connected.

-Computers on the Edge’s optional network.

-Networks that are behind a static route on the trusted or optional interface.

13Click Submit.

Get the user’s .wgx file

The Firebox X Edge makes an encrypted Mobile VPN with IPSec client configuration (.wgx) file for every Firebox User that you give access to. To download a user’s .wgx file:

1To connect to the System Status page, type https:// in the browser address bar, and the IP

address of the Firebox X Edge trusted interface.

The default URL is: https://192.168.111.1

2From the navigation bar, select Firebox Users.

3Below Secure MUVPN Client Configuration Files, select the .wgx file to download by clicking on the link username.wgx where username is the Firebox user’s name.

4At the prompt, save the .wgx file to your computer.

Configuring Global Mobile VPN Client Settings

Some MUVPN client settings apply to all Firebox® X Edge Mobile VPN connections. Select VPN > Mobile User to set these options.

Administrator Guide

3

Image 5
Contents WatchGuardMobile VPN with IPSec Administrator Guide Address Before You Begin About Mobile VPN Client Configuration FilesEnabling Mobile VPN for a Firebox User Account Select the Enable Muvpn for this account check boxGet the user’s .wgx file Configuring Global Mobile VPN Client SettingsDistributing the Software and Profiles Distributing the Software and ProfilesEnd-user profile Distributing the Software and Profiles Mobile User VPN Before You Begin Configuring the Firebox for Mobile VPN Select a user authentication server Configuring the Firebox for Mobile VPN Configuring the external authentication server Adding Users to a Firebox Mobile VPN Group Modifying an Existing Mobile VPN ProfileConfirm Use a certificate Phase2 Settings Defining advanced Phase 1 settings Allowing Internet access through Mobile VPN tunnels Configuring Wins and DNS ServersOn the Mobile User VPN tab, click Advanced Locking Down an End-User ProfileSeeing details on an Mobile VPN policy Configuring Policies to Filter Mobile VPN TrafficAdd individual policies Saving the Profile to a Firebox Using the Any PolicyRe-creating End-User Profiles Making outbound IPSec connections from behind a Firebox Additional Mobile VPN TopicsAdding feature keys Global VPN settingsTerminating IPSec connections Seeing the number of Mobile VPN licensesMobile VPN Client Installation and Connection Installing the Mobile VPN with IPSec Client Window AutoStart No Autostart Select Configuration Profile ImportImporting the end-user profile Selecting a certificate and entering the PIN Connecting the Mobile VPN ClientUninstalling the Mobile VPN client Start All Programs WatchGuard Mobile VPN Mobile VPN Monitor Disconnecting the Mobile VPN clientControlling connection behavior Mobile User VPN client icon Seeing Mobile VPN Log MessagesEnabling the link firewall Securing Your Computer with the Mobile VPN FirewallEnabling the desktop firewall Configuration Firewall SettingsAbout the desktop firewall Creating firewall rules Defining friendly networksGeneral tab Local tab Remote tab