EasyManua.ls Logo

SonicWALL SMA - Role-Based Administration; Sharing Configuration Data; Single Sign-On; System Monitoring and Logging

SonicWALL SMA
48 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
AboutSonicWallSMAConnectTunnel
10
Ontheotherhand,employeesconnectingtoWebresourcesmaytrustaselfsignedcertificate.Even
then,youmaywanttoobtainathirdpartycertificatesothatusersarenotpromptedtoaccepta
selfsignedcertificateeachtimetheyconnect.Or,addtheselfsignedcertificatetothe
userslistof
TrustedRootCertificateAuthoritiesintheWebbrowser.
SingleSignOn
SingleSignOn(SSO)isanoptionthatcontrolswhetherusercredentialsareforwardedtobac kendWeb
resources.ConfiguringtheappliancetouseSSOpreventstheuserfromhavingtologinmultipletimes(onceto
gettotheappliance,andagaintoaccessanapplicationresource).Theappliancesupports
severaltypesof
WebbasedSSO:
•Basicauthenticationforwardingisawidelysupportedformofauthenticationforwarding,butisnotvery
securebecauseitsendspasswordsintheclearacrossthenetwork.Theappliancecanbeconfiguredto
sendeachusersuniqueauthenticationcredentials,orstaticcredentials(thatis,thesame
credentialsfor
allusers).BasicauthenticationforwardingisconfiguredwithinaWebapplicationprofile,whichis
assignedtoone ormoreapplicationresourcesinAMC.
•DomainauthenticationforwardingprovidesasecuremethodforsendingWindowsnetworkcredentials
toaMicrosoftIIS(InternetInformationServices)Webserver.NTLM(WindowsNTLANManager,
also
knownasWindowsNTchallenge/responseauthentication)usesachallenge/responsemechanismto
securelyauthenticateuserswithoutsendingpasswordsintheclearacrossthenetwork.Domain
authenticationforwardingpassesaWindowsdomainnamealongwiththeusersauthentication
credentials.
RSAClearTrustisathirdpartyproductthatprovidesacentralizedmechanism
foradministering
authenticationandsinglesignon.Youcanconfiguretheappliancetoreceiveuserauthentication
credentialsandforwardthemtoanybackendWebresourcesitisprotecting.
SharingConfigurationData
Tokeepsettingsmatchedup,youcanreplicateanddistributeconfigurationdatatoagroupofSonicWall
appliances.Forexample,youmightha veappliancesindifferentlocationsthatmustshareconfigurations.Thisis
notamergingofdata:someofthesettingsonthereceivingapplian cesareoverwritten(securitypolicyand
CA
certificates,forexample),andothersarenot(networksettings).
Whenyoudefineacollectionofappliancesthatwillsharesettings,thenodesinthecollectioncommunicate
overtheinternalinterfaceusingSSL.Theyoperateinpeertopeermode:replicationcanbeinitiatedfromany
systemthatknowsthe
sharedsecretforacollection.Thisisincontrasttothesynchronizationthatoccursina
highavailabilityclusterofSonicWallappliances,inwhichonenodeisdesignatedthemaster.
RolebasedAdminist ration
PermissiontomanagetheapplianceandperformspecificadministrationfunctionsusingAMCisassignedin
AMC.Theprimaryadministratordefinestherolesandidentitiesofallsecondaryadministrators,settingthe
permissionlevelsforeachadministrativerole,andcreatingapasswordprotectedaccountforeach
administrator.
SystemMonitoringandLogging
Systemmonitoringandlog gingfeaturesallowadministratorstoviewbothrealtimeandhistoricaldataabout
theperformanceoftheapplianceanditsaccessservices,aswellasuseractivity.

Table of Contents

Related product manuals