21.6 Example of a more complex Kerio VPN configuration

Configuration of the Paris filial

1.Install WinRoute (version 6.1.0 or higher) at the default gateway of the filial’s net- work.

2.Use Network Rules Wizard (see chapter 6.1) to configure the basic traffic policy in WinRoute. To keep the example as simple as possible, it is supposed that the access from the local network to the Internet is not restricted, i.e. that access to all services is allowed in step 4.

Figure 21.55 The Paris filial — no restrictions are

applied to accessing the Internet from the LAN

In this case, it would be meaningless to create rules for the Kerio VPN server and/or the Kerio Clientless SSL-VPN , since the server uses a dynamic public IP address). Therefore, leave these options disabled in step 5.

Figure 21.56 The Paris filial — default rules for Kerio VPN will not be created

347

Page 347
Image 347
Kerio Tech Firewall6 manual Configuration of the Paris filial, 347