Chapter 24 SSL VPN

Table 121 VPN > SSL VPN > Access Privilege > Add/Edit (continued)

LABEL

DESCRIPTION

SSL Application

The Selectable Application Objects list displays the name(s) of the

List (Optional)

SSL application(s) you can select for this SSL access policy.

 

To associate an SSL application to this SSL access policy, select a name

 

and click >> to add to the Selected Application Objects list. You can

 

select more than one application.

 

To remove an SSL application, select the name(s) in the Selected

 

Application Objects list and click <<.

 

 

Network

 

Extension

 

(Optional)

 

 

 

Enable Network

Select this option to create a VPN tunnel between the authenticated

Extension

users and the internal network. This allows the users to access the

 

resources on the network as if they were on the same local network.

 

Clear this option to disable this feature. Users can only access the

 

applications as defined by the selected SSL application settings and the

 

remote user computers are not made to be a part of the local network.

 

 

Assign IP Pool

Define a separate pool of IP addresses to assign to the SSL users. Select

 

it here.

 

The SSL VPN IP pool cannot overlap with IP addresses on the ZyWALL's

 

local networks (LAN and DMZ for example), the SSL user's network, or

 

the networks you specify in the SSL VPN Network List.

 

 

DNS/WINS

Select the name of the DNS or WINS server whose information the

Server 1..2

ZyWALL sends to the remote users. This allows them to access devices

 

on the local network using domain names instead of IP addresses.

 

 

Network List

To allow user access to local network(s), select a network name in the

 

Selectable Address Objects list and click >> to add to the Selected

 

Address Objects list. You can select more than one network.

 

To block access to a network, select the network name in the Selected

 

Address Objects list and click <<.

 

 

OK

Click Ok to save the changes and return to the main Access Privilege

 

screen.

 

 

Cancel

Click Cancel to discard all changes and return to the main Access

 

Privilege screen.

 

 

24.3 The SSL Global Setting Screen

Click VPN > SSL VPN and click the Global Setting tab to display the following screen. Use this screen to set the IP address of the ZyWALL (or a gateway device)

416

 

ZyWALL USG 50 User’s Guide