Configuring Authentication and Authorization

Configuring Authentication without Authorization

The Firebox SSL VPN Gateway can be configured to authenticate users without requiring authorization. When users are not authorized, the Firebox SSL VPN Gateway does not perform a group authorization check. The settings from the Default user group are assigned to the user.

To remove authorization requirements from the Firebox SSL VPN Gateway

1On the Authentication tab, select an authorization realm.

2On the Authorization tab, in Authorization type, select No authorization.

The Default Realm

The Firebox SSL VPN Gateway has a permanent realm named Default with the following characteristics:

For a new installation, the Default realm is configured for local authentication.

The authentication type of the Default realm can be changed.

The Default realm cannot be removed unless you immediately replace it with a new Default realm.

The Default realm is assumed when a user enters only a user name when logging on to the Firebox SSL VPN Gateway.

When a user logs on to any other realm, the user must log on using realmName\userName. Therefore, if all of your users are authenticated against one authentication server, configure the Default realm for that type of authentication so that users do not have to enter a realm name when logging on.

Using a Local User List for Authentication

For a new installation, the Default realm is set to local authentication. This enables users to log on to the Firebox SSL VPN Gateway without having to enter a realm name.

If some users authenticate only against the local user list on the Firebox SSL VPN Gateway, you can keep the Default realm set to local authentication. Alternatively, you can create a different realm for local authentication and use the Default realm for another authentication type, as described in “To remove and create a Default realm”.

If all users authenticate against authentication servers, you do not need a realm for local authentication. The Firebox SSL VPN Gateway can check the local user database on the appliance for authentication information if a user fails to authenticate on another authentication server. For example, If you are using LDAP and the authentication fails, users can log on using the local user database.

To authenticate using the local user list on the Firebox SSL VPN Gateway

1On the Authentication tab, open the authentication realm on which you

2 want to configure local authentication.

3 Click the Settings tab.

4 Select Use the local user database on the Firebox SSL VPN Gateway.

5Click Submit.

Note

This check box is unavailable if the realm is configured for local authentication

Administration Guide

63

Page 73
Image 73
WatchGuard Technologies SSL VPN manual Configuring Authentication without Authorization, Default Realm

SSL VPN specifications

WatchGuard Technologies offers a robust SSL VPN solution designed for secure remote access to corporate networks. As businesses increasingly rely on a remote workforce, the need for secure and reliable connectivity has never been more critical. WatchGuard's SSL VPN features advanced security technologies that ensure data integrity and confidentiality while enabling seamless access to applications and resources.

One of the standout features of WatchGuard's SSL VPN is its user-friendly interface. The solution is designed to simplify the user experience, enabling employees to connect to the VPN with minimal complexity. With a straightforward setup process, users can quickly establish secure connections from various devices, including laptops, smartphones, and tablets. This flexibility supports a diverse workforce, allowing employees to work from different locations without compromising security.

In addition to its ease of use, WatchGuard's SSL VPN is built on robust security technologies. It employs end-to-end encryption to safeguard data in transit, ensuring that only authorized users can access sensitive information. By utilizing SSL (Secure Sockets Layer) protocols, the VPN creates a secure tunnel between the user’s device and the corporate network, protecting against potential threats such as eavesdropping or man-in-the-middle attacks.

Moreover, WatchGuard Technologies includes multiple authentication options, adding another layer of security. The solution supports multi-factor authentication (MFA), requiring users to provide additional verification beyond just a password. This could involve mobile device verification or biometric authentication, significantly reducing the risk of unauthorized access.

Another key characteristic of WatchGuard’s SSL VPN is its integration with other WatchGuard security solutions. Businesses can benefit from a comprehensive security posture by leveraging firewalls and intrusion prevention systems along with the SSL VPN. This holistic approach ensures that remote connections are continually monitored and secured against evolving cyber threats.

Scalability is also a crucial aspect of WatchGuard's SSL VPN, accommodating growing organizations with changing needs. The solution can easily scale to support an increasing number of remote users without compromising performance. With robust performance metrics, businesses can ensure that even during peak usage times, the VPN remains responsive and reliable.

In summary, WatchGuard Technologies' SSL VPN solution combines ease of use, robust security, flexible authentication, and scalability. These features make it an ideal choice for organizations seeking to provide secure remote access to their employees while maintaining a strong defense against cyber threats. With WatchGuard, businesses can confidently navigate the challenges of a digital landscape, ensuring their network remains secure as they embrace remote work.