SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
AboutSonicWallSMAConnectTunnel
10
• Ontheotherhand,employeesconnectingtoWebresourcesmaytrustaself‐signedcertificate.Even
then,youmaywanttoobtainathird‐partycertificatesothatusersarenotpromptedtoaccepta
self‐signedcertificateeachtimetheyconnect.Or,addtheself‐signedcertificatetothe
user’slistof
TrustedRootCertificateAuthoritiesintheWebbrowser.
SingleSign‐On
SingleSign‐On(SSO)isanoptionthatcontrolswhetherusercredentialsareforwardedtobac k‐endWeb
resources.ConfiguringtheappliancetouseSSOpreventstheuserfromhavingtologinmultipletimes(onceto
gettotheappliance,andagaintoaccessanapplicationresource).Theappliancesupports
severaltypesof
Web‐basedSSO:
•Basicauthenticationforwardingisawidelysupportedformofauthenticationforwarding,butisnotvery
securebecauseitsendspasswordsintheclearacrossthenetwork.Theappliancecanbeconfiguredto
sendeachuser’suniqueauthenticationcredentials,orstaticcredentials(thatis,thesame
credentialsfor
allusers).BasicauthenticationforwardingisconfiguredwithinaWebapplicationprofile,whichis
assignedtoone ormoreapplicationresourcesinAMC.
•DomainauthenticationforwardingprovidesasecuremethodforsendingWindowsnetworkcredentials
toaMicrosoftIIS(InternetInformationServices)Webserver.NTLM(WindowsNTLANManager,
also
knownasWindowsNTchallenge/responseauthentication)usesachallenge/responsemechanismto
securelyauthenticateuserswithoutsendingpasswordsintheclearacrossthenetwork.Domain
authenticationforwardingpassesaWindowsdomainnamealongwiththeuser’sauthentication
credentials.
• RSAClearTrustisathird‐partyproductthatprovidesacentralizedmechanism
foradministering
authenticationandsinglesign‐on.Youcanconfiguretheappliancetoreceiveuserauthentication
credentialsandforwardthemtoanyback‐endWebresourcesitisprotecting.
SharingConfigurationData
Tokeepsettingsmatchedup,youcanreplicateanddistributeconfigurationdatatoagroupofSonicWall
appliances.Forexample,youmightha veappliancesindifferentlocationsthatmustshareconfigurations.Thisis
notamergingofdata:someofthesettingsonthereceivingapplian cesareoverwritten(securitypolicyand
CA
certificates,forexample),andothersarenot(networksettings).
Whenyoudefineacollectionofappliancesthatwillsharesettings,thenodesinthecollectioncommunicate
overtheinternalinterfaceusingSSL.Theyoperateinpeer‐to‐peermode:replicationcanbeinitiatedfromany
systemthatknowsthe
sharedsecretforacollection.Thisisincontrasttothesynchronizationthatoccursina
high‐availabilityclusterofSonicWallappliances,inwhichonenodeisdesignatedthemaster.
Role‐basedAdminist ration
PermissiontomanagetheapplianceandperformspecificadministrationfunctionsusingAMCisassignedin
AMC.Theprimaryadministratordefinestherolesandidentitiesofallsecondaryadministrators,settingthe
permissionlevelsforeachadministrativerole,andcreatingapassword‐protectedaccountforeach
administrator.
SystemMonitoringandLogging
Systemmonitoringandlog gingfeaturesallowadministratorstoviewbothreal‐timeandhistoricaldataabout
theperformanceoftheapplianceanditsaccessservices,aswellasuseractivity.