Policies_SSLVPN_VirtualOffice_Snwls
To configure the SSL VPN > Virtual Office page, perform the following:
1. Click Add Bookmark. The Add Bookmark window displays.When user bookmarks are defined, the user will see the defined bookmarks from the SonicWALL SSL VPN Virtual Office home page. Individual user members are not able to delete or modify bookmarks created by the administrator.
2. Type a descriptive name for the bookmark in the Bookmark Name field.
3. Enter the fully qualified domain name (FQDN) or the IPv4 address of a host machine on the LAN in the Name or IP Address field. In some environments you can enter the host name only, such as when creating a VNC bookmark in a Windows local network.
Some services can run on non-standard ports, and some expect a path when connecting. Depending on the choice in the Service field, format the Name or IP Address field like one of the examples shown below:.
|
Tip When creating a Virtual Network Computing (VNC) bookmark to a Linux server, you must specify the port number and server number in addition to the Linux server IP the Name or IP Address field in the form of ipaddress:port:server. For example, if the Linux server IP address is 192.168.2.2, the port number is 5901, and the server number is 1, the value for the Name or IP Address field would be 192.168.2.2:5901:1.
4. For the specific service you select from the Service drop-down list, additional fields may appear. Fill in the information for the service you selected. Select one of the following service types from the Service drop-down list:
• Terminal Services (RDP - ActiveX) or Terminal Services (RDP - Java)
Note If you select Terminal Services (RDP - ActiveX) while using a browser other than Internet Explorer, the selection is automatically switched to Terminal Services (RDP - Java). A popup dialog box notifies you of the switch.
– In the Screen Size drop-down list, select the default terminal services screen size to be used when users execute this bookmark. Because different computers support different screen sizes, when you use a remote desktop application, you should select the size of the screen on the computer from which you are running a remote desktop session. Additionally, you may want to provide a path to where your application resides on your remote computer by typing the path in the Application Path field.
– In the Colors drop-down list, select the default color depth for the terminal service screen when users execute this bookmark.
– Optionally enter the local path for this application in the Application and Path (optional) field.
– In the Start in the following folder field, optionally enter the local folder in which to execute application commands.
– Select the Login as console/admin session checkbox to allow login as console or admin. Login as admin replaces login as console in RDC 6.1 and newer.
– For RDP - Java on Windows clients, or on Mac clients running Mac OS X 10.5 or above with RDC installed, expand Show advance Windows options and select the checkboxes for any of the following redirect options: Redirect Printers, Redirect Drives, Redirect Ports, Redirect SmartCards, Redirect clipboard, or Redirect plug and play devices to redirect those devices or features on the local network for use in this bookmark session. You can hover your mouse pointer over the Help icon next to certain options to display tooltips that indicate requirements.
To see local printers show up on your remote machine (Start > Settings > Control Panel > Printers and Faxes), select Redirect Ports as well as Redirect Printers.
Select the checkboxes for any of the following additional features for use in this bookmark session: Display connection bar, Auto reconnection, Desktop background, Window drag, Menu/window animation, Themes, or Bitmap caching.
If the client application will be RDP 6 (Java), you can select any of the following options as well: Dual monitors, Font smoothing, Desktop composition, or Remote Application.
Remote Application monitors server and client connection activity; to use it, you need to register remote applications in the Windows 2008 RemoteApp list. If Remote Application is selected, the Java Console will display messages regarding connectivity with the Terminal Server.
– For RDP - ActiveX on Windows clients, optionally select Enable plugin DLLs and enter the name(s) of client DLLs which need to be accessed by the remote desktop or terminal service. Multiple entries are separated by a comma with no spaces. Note that the RDP Java client on Windows is a native RDP client that supports Plugin DLLs by default. The Enable plugin DLLs option is not available for RDP - Java. See Enabling Plugin DLLs.
– Optionally select Automatically log in and select Use SSL VPN account credentials to forward credentials from the current SSL VPN session for login to the RDP server. Select Use custom credentials to enter a custom username, password, and domain for this bookmark. For more information about custom credentials, see Creating Bookmarks with Custom SSO Credentials.
• Virtual Network Computing (VNC)
– No additional fields
• Telnet
– No additional fields
• Secure Shell version 1 (SSHv1)
– No additional fields
• Secure Shell version 2 (SSHv2)
– Optionally select the Automatically accept host key checkbox.
– If using an SSHv2 server without authentication, such as a SonicWALL firewall, you can select the Bypass username checkbox.
5. Click Add to update the configuration.
The plugin DLLs feature is available for RDP (ActiveX or Java), and allows for the use of certain third party programs such as print drivers, on a remote machine. This feature requires RDP Client Control version 5 or higher.
Note The RDP Java client on Windows is a native RDP client that supports Plugin DLLs by default. No action (or checkbox) is needed.
To enable plugin DLLs for the RDP ActiveX client:
1. Navigate to Users > Local Users.
2. Click the configure icon corresponding to the user bookmark you wish to edit.
3. In the Bookmarks tab, click Add Bookmark.
4. Select Terminal Services (RDP - ActiveX) as the Service and configure as described in the section Configuring Virtual Office.
5. Enter the name(s) of client DLLs which need to be accessed by the remote desktop or terminal service. Multiple entries are separated by a comma with no spaces.
6. Ensure that any necessary DLLs are located on the individual client systems in %SYSTEMROOT% (for example: C:\Windows\system32 ).
Note Ensure that your Windows system and RDP client are up to date prior to using the Plugin DLLs feature. This feature requires RDP 5 Client Control or higher.
Creating Bookmarks with Custom SSO Credentials
The administrator can configure custom Single Sign On (SSO) credentials for each user, group, or globally in RDP bookmarks. This feature is used to access resources that need a domain prefix for SSO authentication. Users can log into SonicWALL SSL VPN as username, and click a customized bookmark to access a server with domain\username. Either straight textual parameters or variables may be used for login credentials.
To configure custom SSO credentials, perform the following steps:
1. Create or edit an RDP bookmark as described in Configuring Virtual Office.
2. In the Bookmarks tab, select the Use Custom Credentials option.
3. Enter the appropriate username and password, or use dynamic variables as follows:
|
4. Click Add.