SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN
16
WhichTypesof ResourcesShouldUsersHaveAccess
To?
TheSonicWallSMAappliancemanagesawidevarietyofcorporateresources,whichfallintothecategories
describedinTypesofuserresources.
Topics:
• HowWillUsersAccessYourResources?onpage16
• Tunnel,Proxy,orWeb:WhichAccessMethodisBest?onpage16
HowWillUsersAccessYourResources?
UserscanaccessVPNresourcessecuredbytheapplianceusingavarietyofagentsandclients.Yourdeployment
optionscanrangeanywherefrom“managed”desktopscontrolledbyyourITdepartment,tosystemsoutsideof
yourcontrol,includingemployees’homecomputers,partnerdesktops,andothersystemssuchaskiosksor
handhelddevices.
Howusersgainaccesstoyournetworkresourcesdependsonwhatthoseresourcesare.TheConnectTunnel
client,forexample,isinstalledontheuser’sdeviceandprovidesthebroadestnetworkaccessandsupport,and
greatesteaseofadministration.TheOnDemandagentalsoprovidesbroadcross‐platformsupport,butdoes
not
handlebi‐directionalapplicationslikeVoIP.
Tunnel,Proxy,orWeb:WhichAccessMethodisBest?
TheSMAaccessservicesandclientsofferawidearrayofmethodswithdifferentdegreesofcapabilityfor
reachingyourorganization’sresources.Usethetablebelowtodeterminewhichonesarebestforyouandyour
users.
Otherfactorstoconsider, asidefromtechnicalrequirements,are:
•Securityrequirementssuchasthe
safeguardsyouwanttoputinplaceonthedesktop.
•Userprofi les,includingthelevelsoftechnicalsophisticationamongyourusers.
Typesofuserresources
Resourcetype Examples Planningconsiderations
Web MicrosoftOutlookWeb
Access
Web‐basedapplications
Webportals
Webservers
• WhenspecifyingURLstoWebresources,includethe
http://orhttps://prefix.
• Usealiasesto
obscurehostnamesonprivate
networks.
Client/server Terminalservers(suchas
CitrixorWTS)
MicrosoftOutlookLotus
Notes
• Identifyresourcesbyhostname,IPaddressorIP
range,subnetIPaddress,ordomainname.
FileShares Networkfolders
Sharedfolders
Networkbrowsing
Windowsdomains
• Aspecificfilesystemresourcecanbeanentireserver
(forex ample,\\ginkgo),asharedfolder
(\\john\public),oranetworkfolder
(\\ginkgo\news).
• DefiningaWindowsdomaingivesauthorizedusers
accesstoallnetworkfileresources.