For information on configuring SSL VPN bookmarks, see “Editing Local Users” in the Users Management chapter.
Click Add Bookmark . The Add Bookmark window displays.When user bookmarks are defined, the user will see the defined bookmarks from the SonicWALL SSL VPN Virtual Office home page. Individual user members are not able to delete or modify bookmarks created by the administrator.
Step 1
|
Type a descriptive name for the bookmark in the
Bookmark Name
field.
|
Step 2
|
Enter the fully qualified domain name (FQDN) or the IPv4 address of a host machine on the
LAN in the Name or IP Address
field. In some environments you can enter the host name only, such as when creating a VNC bootmark in a Windows local network.
|
Some services can run on non-standard ports, and some expect a path when connecting. Depending on the choice in the Service field, format the Name or IP Address field like one of the examples shown in Table 1 .
Example for
Name or IP Address Field
|
||
Note : Do not use session or display number instead of port. |
10.20.30.4:5901 (mapped to session 1) JBJONES-PC.sv.us.sonicwall.com Note : Do not use 10.20.30.4:1 Tip : For a bookmark to a Linux server, see the Tip below this table. |
|
Tip
|
When creating a
Virtual Network Computing (VNC)
bookmark to a Linux server, you must specify the port number and server number in addition to the Linux server IP the Name or
IP Address
field in the form of ipaddress:port:server
. For example, if the Linux server IP address is 192.168.2.2, the port number is 5901, and the server number is 1, the value for the Name or IP Address
field would be 192.168.2.2:5901:1
.
|
Step 3
|
For the specific service you select from the
Service
drop-down list, additional fields may appear. Fill in the information for the service you selected. Select one of the following service types from the Service drop-down list:
|
Note
|
If you select
Terminal Services (RDP - ActiveX)
while using a browser other than Internet Explorer, the selection is automatically switched to Terminal Services (RDP - Java)
. A popup dialog box notifies you of the switch.
|
–
|
In the
Screen Size
drop-down list, select the default terminal services screen size to be used when users execute this bookmark.
|
Because different computers support different screen sizes, when you use a remote desktop application, you should select the size of the screen on the computer from which you are running a remote desktop session. Additionally, you may want to provide a path to where your application resides on your remote computer by typing the path in the Application Path field.
–
|
In the
Colors
drop-down list, select the default color depth for the terminal service screen when users execute this bookmark.
|
–
|
–
|
In the
Start in the following folder
field, optionally enter the local folder in which to execute application commands.
|
–
|
Select the
Login as console/admin session
checkbox to allow login as console or admin. Login as admin replaces login as console in RDC 6.1 and newer.
|
–
|
For
RDP - Java
on Windows clients, or on Mac clients running Mac OS X 10.5 or above with RDC installed, expand Show advance Windows options
and select the checkboxes for any of the following redirect options: Redirect Printers
, Redirect
Drives
, Redirect Ports
, Redirect SmartCards
, Redirect clipboard
, or Redirect plug
and play devices
to redirect those devices or features on the local network for use in this bookmark session. You can hover your mouse pointer over the Help icon
![]() To see local printers show up on your remote machine (Start > Settings > Control Panel > Printers and Faxes), select Redirect Ports as well as Redirect Printers . Select the checkboxes for any of the following additional features for use in this bookmark session: Display connection bar , Auto reconnection , Desktop background , Window drag , Menu/window animation , Themes , or Bitmap caching . If the client application will be RDP 6 (Java), you can select any of the following options as well: Dual monitors , Font smoothing , Desktop composition , or Remote Application . Remote Application monitors server and client connection activity; to use it, you need to register remote applications in the Windows 2008 RemoteApp list. If Remote Application is selected, the Java Console will display messages regarding connectivity with the Terminal Server. |
–
|
For
RDP - ActiveX
on Windows clients, optionally select Enable plugin DLLs
and enter the name(s) of client DLLs which need to be accessed by the remote desktop or terminal service. Multiple entries are separated by a comma with no spaces. Note that the RDP Java client on Windows is a native RDP client that supports Plugin DLLs by default. The Enable plugin DLLs
option is not available for RDP - Java. See “Enabling Plugin DLLs” section
.
|
–
|
Optionally select
Automatically log in
and select Use SSL VPN account credentials
to forward credentials from the current SSL VPN session for login to the RDP server. Select Use custom credentials
to enter a custom username, password, and domain for this bookmark. For more information about custom credentials, see “Creating Bookmarks with Custom SSO Credentials” section
.
|
–
|
Optionally select the
Automatically accept host key
checkbox.
|
–
|
If using an SSHv2 server without authentication, such as a SonicWALL firewall, you can
select the Bypass username
checkbox.
|
Step 4
|
Click
Add
to update the configuration.
|
The plugin DLLs feature is available for RDP (ActiveX or Java), and allows for the use of certain third party programs such as print drivers, on a remote machine. This feature requires RDP Client Control version 5 or higher.
Note
|
The RDP Java client on Windows is a native RDP client that supports Plugin DLLs by
default. No action (or checkbox) is needed.
|
To enable plugin DLLs for the RDP ActiveX client:
Step 1
|
Navigate to
Users > Local Users
.
|
Step 3
|
Step 4
|
Select
Terminal Services (RDP - ActiveX)
as the Service
and configure as described in the section “Configuring SSL VPN Bookmarks”
.
|
Step 5
|
Enter the name(s) of client DLLs which need to be accessed by the remote desktop or terminal
service. Multiple entries are separated by a comma with no spaces.
|
Step 6
|
Ensure that any necessary DLLs are located on the individual client systems in
%SYSTEMROOT% (for example: C:\Windows\system32 ).
|
Note
|
Ensure that your Windows system and RDP client are up to date prior to using the Plugin
DLLs feature. This feature requires RDP 5 Client Control or higher.
|
The administrator can configure custom Single Sign On (SSO) credentials for each user, group, or globally in RDP bookmarks. This feature is used to access resources that need a domain prefix for SSO authentication. Users can log into SonicWALL SSL VPN as username , and click a customized bookmark to access a server with domain\username . Either straight textual parameters or variables may be used for login credentials.
To configure custom SSO credentials, perform the following steps:
Step 2
|
Step 4
|
Click
Add
.
|
The following sections describe how to use the various types of bookmarks:
Remote Desktop Protocol (RDP) bookmarks enable you to establish remote connections with a specified desktop. SonicWALL SSL VPN supports the RDP5 standard with both Java and ActiveX clients. RDP5 ActiveX can only be used through Internet Explorer, while RDP5 Java can be run on any platform and browser supported by the SonicWALL SSL VPN. The basic functionality of the two clients is the same; however, the Java client is a native RDP client and supports the following features that the ActiveX client does not:
•
|
If the Java client application is RDP 6, it also supports:
Tip
|
To terminate your remote desktop session, be sure to log off from the Terminal Server
session. If you wish to suspend the Terminal Server session (so that it can be resumed later) you may simply close the remote desktop window.
|
Step 1
|
Click on the
RDP
bookmark. Continue through any warning screens that display by clicking Yes
or Ok
.
|
Step 2
|
Enter your username and password at the login screen and select the proper domain name
from the pull-down menu.
|
Step 3
|
A window is displayed indicating that the Remote Desktop Client is loading. The remote
desktop then loads in its own windows. You can now access all of the applications and files on the remote computer.
|
Step 2
|
When the VNC client has loaded, you will be prompted to enter your password in the
VNC
Authentication
window.
|
Step 3
|
Table 2 describes the options that can be configured for VNC.
Table 2
|
Hextile is a good choice for fast networks, while Tight is better suited for low-bandwidth connections. From the other side, the Tight decoder in TightVNC Java viewer is more efficient than Hextile decoder so this default setting can also be acceptable for fast networks.
Use specified compression level for Tight and Zlib encodings. Level 1 uses minimum of CPU time on the server but achieves weak compression ratios. Level 9 offers best compression but may be slow in terms of CPU time consumption on the server side. Use high levels with very slow network connections, and low levels when working over higher-speed networks. The Default value means that the server's default compression level should be used.
Cursor shape updates is a protocol extension used to handle remote cursor movements locally on the client side, saving bandwidth and eliminating delays in mouse pointer movement. Note that current implementation of cursor shape updates does not allow a client to track mouse cursor position at the server side. This means that clients would not see mouse cursor movements if the mouse was moved either locally on the server, or by another remote VNC client.
Set this parameter to Disable if you always want to see real cursor position on the remote side. Setting this option to Ignore is similar to Enable but the remote cursor will not be visible at all. This can be a reasonable setting if you don't care about cursor shape and don't want to see two mouse cursors, one above another.
CopyRect saves bandwidth and drawing time when parts of the remote screen are moving around. Most likely, you don't want to change this setting.
If set to No , then 24-bit color format is used to represent pixel data. If set to Yes , then only 8 bits are used to represent each pixel. 8-bit color format can save bandwidth, but colors may look very inaccurate.
If set to Reversed , the right mouse button (button 2) will act as if it was the middle mouse button (button 3), and vice versa.
If set to Yes , then all keyboard and mouse events in the desktop window will be silently ignored and will not be passed to the remote side.
If set to Yes , then the desktop can be shared between clients. If this option is set to No then an existing user session will end when a new user accesses the desktop.
Step 2
|
Click
OK
to any warning messages that are displayed. A Java-based Telnet window launches.
|
Step 3
|
Tip
|
Step 1
|
Click on the SSHv2 bookmark. A Java-based SSH window displays. Type your user name in
the Username
field and click Login
.
|
Step 2
|
A hostkey popup displays. Click
Yes
to accept and proceed with the login process.
|
Step 3
|