The
SSL VPN > Client Settings
page allows the administrator to enable SSL VPN access on zones and configure the client address range information and NetExtender client settings. It also displays which zones have SSL VPN access enabled.
The following tasks are configured on the
SSL VPN > Client Settings
page:
All of the zones on the SonicWALL security appliance are displayed in the
SSL VPN Status on
Zones
section of the SSL VPN > Client Settings
page. SSL VPN access must be enabled on a zone before users can access the Virtual Office web portal. A green button to the left of the name of the zone indicates that SSL VPN access is enabled. A red button indicates that SSL VPN access is disabled. To change the SSL VPN access for a zone, simply click the name of the zone on the SSL VPN > Client Settings
page.
SSL VPN Access can also be configured on the
Network > Zones
page by clicking the configure icon for the zone.
The SSL VPN Client Address Range defines the IP address pool from which addresses will be
assigned to remote users during NetExtender sessions. The range needs to be large enough to accommodate the maximum number of concurrent NetExtender users you wish to support plus one (for example, the range for 15 users requires 16 addresses, such as 192.168.200.100 to 192.168.200.115).
To configure the SSL VPN Client Address Range, perform the following steps:
Step 7
|
Navigate to the
SSL VPN
> Client Settings
page.In the NetExtender Start IP
field, enter the first IP address in the client address range.
|
Step 8
|
In the
NetExtender End IP
field, enter the last IP address in the client address range.
|
Step 9
|
In the
DNS Server 1
field, enter the IP address of the primary DNS server, or click the Default
DNS Settings
to use the default settings.
|
Step 10
|
(Optional) In the
DNS Server 2
field, enter the IP address of the backup DNS server.
|
Step 11
|
(Optional) In the
DNS Domain
field, enter the domain name for the DNS servers.
|
|
Note
|
For appliances supporting connections from Apple iPhones, iPads, or other iOS devices
using SonicWALL Mobile Connect, the DNS Domain is a required field. This DNS domain is set on the VPN interface of the iPhone/iPad after the device makes a connection to the appliance.
When the mobile device user accesses a URL, iOS determines if the domain matches the VPN interface's domain, and if so, uses the VPN interface's DNS server to resolve the hostname lookup. Otherwise, the Wi-Fi or 3G DNS server is used, which will not be able to resolve hosts within the company intranet.
|
Step 12
|
In the
User Domain
field, enter the domain name for the users. The value of this field must match the domain field in the NetExtender client.
|
Step 13
|
(Optional) In the
WINS Server 1
field, enter the IP address of the primary WINS server.
|
Step 14
|
(Optional) In the
WINS Server 2
field, enter the IP address of the backup WINS server.
|
Step 15
|
In the
Interface
pulldown menu, select the interface to be used for SSL VPN services.
|
NetExtender client settings are configured on the bottom of the
SSL VPN > Client Settings
page. The following settings to customize the behavior of NetExtender when users connect and disconnect.
|
•
|
Exit Client After Disconnect
- The NetExtender client exits when it becomes disconnected from the SSL VPN server. To reconnect, users will have to either return to the SSL VPN portal or launch NetExtender from their Programs menu.
|
|
•
|
Uninstall Client After Disconnect
- The NetExtender client automatically uninstalls when it becomes disconnected from the SSL VPN server. To reconnect, users will have to return to the SSL VPN portal.
|
|
•
|
Create Client Connection Profile
- The NetExtender client will create a connection profile recording the SSL VPN Server name, the Domain name and optionally the username and password.
|
|
•
|
User Name & Password Caching
- Provide flexibility in allowing users to cache their usernames and passwords in the NetExtender client. The three options are Allow saving
of user name only
, Allow saving of user name & password
, and Prohibit saving of
user name & password
. These options enable administrators to balance security needs against ease of use for users.
|