SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN
18
SecurityAdministration
Administeringyoursecuritypolicyinvolvesdefiningresourcesandthencreatingaccesscontrolrulesthat
determinetheavailabilityofthoseresources.
Topics:
• DefiningResourcesonpage18
• ManagingAccessControlwithanAccessPolicyonpage20
• AccessControlforBi‐DirectionalConnectionsonpage21
• DesignGuidelinesforAccessRulesonpage22
DefiningResources
Youhavesomeflexibilitywhenyouspecifyaresourcetypeforagivenobjectonyournetwork.Forexample,you
mightdefineaWebapplicationnarrowlyasaURLresourceforbusinesspartners;employees,ontheother
hand,mightbegivenaccesstoanentiredomain,includingtheWebapplication.
Topics:
• WebResourcesonpage19
• Client/ServerResourcesonpage19
• FileSharesonpage20
TranslatedWeb
access
CustomPort
MappedWeb
access
CustomFQDN
MappedWeb
access
AnyWebresource
(includingWeb‐based
applications,Webportals,
andWebservers).
TranslatedWebon
Windowsoperating
systemsalsooffersaccess
tonetworkshares.
CustomPortMapping
providesaccessviaa
specificportdefinedby
theadministrator,which
mustbeopenonthe
externalfirewall.
CustomFQDNMapping
providesaccessviaDNS
andrequiresnewDNS
entriesandpossiblyanew
SSLcertificateandIP
address.
ConvenientaccesstoWebandfilesystemresourcesfrom
anyWebbrowserthatsupportsSSLandhasJavaScript
enabled.
Noclientconfigurationoradministrationtasks.
Supportstheuseofaliasestohideinternalhostnamesinthe
browseraddressbar.
Singlesign‐ontoback‐endWebservers.
Agoodoptionforprovidingbusinesspartneraccess,because
itdoesnotrequireany
clientconfigurationoradministration.
CustomPortMappingandCustomFQDNMappinghandle
WebprogrammingtechnologiessuchasAJAXwithoutthe
limitationsofURLrewritingusedintranslation.
Accessmethodadvantages
AccessMethod ProvidesAccessto Advantages