vii
Configuring IPsec VPN ··········································································································································· 350
Overview ······································································································································································· 350
Recommended configuration procedure···················································································································· 350
Configuring an IPsec connection ································································································································ 351
Displaying IPsec VPN monitoring information ·········································································································· 358
IPsec VPN configuration example ······························································································································ 359
Configuration guidelines ············································································································································· 361
Configuring L2TP ····················································································································································· 363
Enabling L2TP ······························································································································································· 364
Adding an L2TP group ················································································································································ 364
Displaying L2TP tunnel information ···························································································································· 370
Client-initiated VPN configuration example ·············································································································· 370
Configuring GRE ····················································································································································· 375
Overview ······································································································································································· 375
Configuring a GRE over IPv4 tunnel ·························································································································· 375
Recommended configuration procedure ··········································································································· 375
Creating a GRE tunnel ········································································································································ 375
GRE over IPv4 tunnel configuration example ············································································································ 377
SSL VPN overview ··················································································································································· 384
How SSL VPN works ···················································································································································· 384
Advantages of SSL VPN ·············································································································································· 385
Configuring SSL VPN gateway ······························································································································ 386
Recommended configuration procedure···················································································································· 386
Configuring the SSL VPN service ······························································································································· 387
Configuring Web proxy server resources ················································································································· 389
Configuring TCP application resources ····················································································································· 391
Configuring a remote access service resource ································································································· 392
Configuring a desktop sharing service resource ····························································································· 393
Configuring an email service resource ············································································································· 394
Configuring a Notes service resource ··············································································································· 395
Configuring a common TCP service resource ·································································································· 397
Configuring IP network resources ······························································································································· 398
Recommended configuration procedure ··········································································································· 398
Configuring global parameters ·························································································································· 398
Configuring host resources ································································································································· 399
Configuring a user-IP binding ···························································································································· 401
Configuring a predefined domain name ·········································································································· 402
Configuring a resource group ···································································································································· 403
Configuring local users ················································································································································ 405
Adding a local user manually ···························································································································· 405
Importing local users in bulk ······························································································································ 407
Configuring a user group ············································································································································ 408
Viewing user information ············································································································································ 410
Viewing online user information ························································································································ 410
Logging out an online user ································································································································· 410
Viewing history user information ······················································································································· 410
Performing basic configurations for the SSL VPN domain ······················································································· 411
Configuring the domain policy ·························································································································· 411
Configuring the caching policy ························································································································· 413
Configuring a bulletin ········································································································································· 413
Configuring authentication policies ··························································································································· 414
Configuring local authentication ······················································································································· 415