Configuring Advanced Remote Access Options
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 229
Configuring Advanced Remote Access Options
In the VPN > Remote Access Advanced page you can configure more advanced settings to determine VPN
remote access users' behavior.
You can also add bookmarks (HTML links or RDP links) for specified URLs or computers when you connect
through SSL VPN (see below). The next time you log in, your bookmarks are shown.
Office Mode
Remote access VPN clients connect through a VPN tunnel from their homes to the appliance and from there
they can gain access into the organization's resources.
The appliance assigns each remote access user an IP address from a specified network so that the traffic
inside the organization is not aware that it originated from outside the organization.
This technology is called Office Mode and the network used for supplying the IP addresses is configurable.
To configure the Office Mode network:
1. Enter the Office Network address and Office Subnet Mask.
2. Click Apply.
The default setting for office mode is 172.16.10.0/24.
To assign a VPN certificate:
1. Click the downward arrow next to the VPN Remote Access certificate field.
The list of uploaded certificates shows.
2. Select the desired certificate.
Note - You cannot select the default Web portal certificate.
3. Click Apply.
To route all traffic from VPN remote access clients through the gateway:
1. Select the Route Internet traffic from connected clients through this gateway checkbox.
2. Click Apply.
Normally, only traffic from the VPN clients into the organization's encryption domain is encrypted and sent
through the VPN tunnel to the gateway. Selecting the above checkbox causes all traffic from the VPN clients
to be encrypted and sent to the gateway. Traffic to locations outside the organization are enforced in this
case by the outgoing access Policy. For more information, see Access Policy Firewall Blade Control and
Policy pages.
Note - This setting does not apply to traffic from SSL Network Extender clients.