SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN
19
WebResources
AnyWebresource—suchasaWebapplication,aWebportal,oraWebserver—canbedefinedasaURL
resource(theyarespecifiedinAMCusingthestandardhttp://orhttps://URLsyntax).Examplesinclude
MicrosoftOutlookWebAccessandotherWeb‐basede‐mailprograms,Webportals,corporateintranets,and
standardWebservers.
DefiningaWebresourceasaURLprovidesseveraladvantages:
• YoucancreateaWebshortcutonWorkPlacetogiveusersquickaccess.
• Youcandefineverys pec ificaccessrulestocontrolwhichuserscanaccesstheURL.
• Youhavetheoptionofobscuring(or“ aliasing”)the
internalhostnamesoitisnotpubliclyexposed.
• Youcanblockattachmentsfrombeingdownloadedtountrusteddevices,orpreventaWeb‐based
applicationfromdisplayingrestricteddatatountrusteddevices.
WebtrafficisproxiedthroughtheWebproxyservice,asecuregatewaythroughwhichuserscanaccessprivate
WebresourcesfromtheInternet.
Client/ServerResources
Client/serverresourcesencompassapplications,fileservers,andmultiple Webresourcesandarespecifiedin
AMCusingeitheradomain,subnet,IPrange,hostname,orIPaddress:
• Client/serverapplicationsinclude“traditional”applicationsdevelopedforaparticularoperatingsystem,
orthin‐clientapplicationsthatareWeb‐based.
•NetworksharesincludeWindowsfile
serversorfileshares.Networksharesareaccessibleusingeither
OnDemandorConnectTunnel.(ToaccessanetworkshareusingaWebbrowser,youmustinsteaddefine
itasafi lesystemresource.)
•Sourcenetworksarereferencedinanaccessruletopermitordenyaconnectiontoadestination
resource
basedonthelocationfromwhichtherequestoriginates.Forexample,youmightpermit
connectionsonlyfromaparticulardomain,orpermitthemonlyfromaspecificIPaddress.
•GraphicalterminalagentscanbeaddedtoWorkPlaceasshortcutsthatprovideaccesstoaterminal
server(orCitrixserverfarm)using
aWindowsTerminalServicesorCitrixcl ient.
•MultipleWebresourcesonyournetwork—whetherinadomain,subnet,orIPrange—canbedefined.
ThisisaconvenientwayforyoutoadministermultipleWebserversfromasingleresourceinAMC.For
example,ifyouspecifyadomain(andcreatetheappropriate
accessrule),usersareabletousetheir
WebbrowserstoaccessanyWebresourcescontainedwithinthatdomain.TheycanalsouseOnDemand
orConnectTunneltogettothoseresources.
Onthedownside,however,youruserscannotaccessthoseresourcesfromashortcutonWorkPlace;
instead,theymustknow
theinternalhostnameoftheresource.IftheWebproxyagentisrunning,they
canenteranyURLdirectlyinthebrowser.However,intranslatedmode,usersmustmanuallytypeURLs
intheIntranetAddressboxinWorkPlace.
Withsuchawidescopeofresourcedefinitions—frombroadresourcessuchas
adomainorsubnet,downtoa
singlehostorIPaddress—youmaywonderhowbesttodefineyournetworkresources.Broadresource
definitionssimplifyyourjobassystemadministrator,andaretypicallyusedwhenmanagingaremoteaccess
VPNwithanopenaccesspolicy.Forexample,youcoulddefine
yourinternalDNSnamespaceasadomainand
createasinglepolicyrulegrantingemployeesaccessprivileges.
Ontheotherhand,amorerestrictivesecuritypolicyrequiresyoutodefinenetworkresourcesmorenarrowly.
ThisapproachistypicallyusedwhenadministeringapartnerVPN.Forexample,toprovideanexternalsupplier
withaccesstoaninventoryapplication,youmightspecifyitshostnameasaresourceandcreateapolicyrule
specificallygrantingthesupplieraccessprivileges.