SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN
24
Authenticatingwithrealmsandcommunities
Ifyournetworkusesasingle authenticationservertostoreuserinformation,you’llprobablyneedtocreateonly
onerealminAMC.Thatrealmcouldthenreferencethe globalcommunitythatisconfiguredbydefaultinAMC.
Thiswouldbeusefulifyouhaveahomogenous
userpopulationwithidenticalaccessrequirements.
Usingonlyonerealmdoesn’tlimityourabilitytoconfiguremoregranularlevelsofuseraccessandEndPoint
Control.AMCallowsyoutocreatecommunitiesofuserswithinarealmbasedontheiraccessneedsorother
securityconsiderations.Acommunitycanconsistof
alltheusersinarealm,oronlyselectedusersorgroups.
Forexample,youmighthavetwodistinctgroupsofusers—employeesandbusinesspartners—requiring
differentformsofVPNaccess.TheEmployeecommunityandBusinesspartnercommunitytablescontrastthe
accessagentsthataremadeavailabletothesetwogroups,and
howEPCisusedtosecuretheirconnections.By
creatingdifferentWorkPlacestylesandlayoutsyoualsocandeterminehowWorkPlacelookstomembersof
thesetwocommunities.
Employeecommunity
AccessAgent EPC
Atunnelclient,enablingthemto
accessWeb,network,andfile
shareresources.
EPCisusedtodetectwhetheremployees’
computersarerunningan
antivirusprogr a mandfirewallbefor eplacingtheminatrustedzone.
Usersconnectfromtrustedcomputingenvironments(suchaslaptopsprovidedbyyourITdepartment)and
requirebroadaccesstoyournetworkresources.
Businesspartnercommunity
AccessAgent EPC
Limited,Web‐onlyaccess Businesspartnersareassignedtoaless‐
trustedzonewheretheyare
provisionedwithCacheCleaner.
Partnersconnectthroughunsecuredcomputingenvironmentsandrequireaccessonlytospecific,limited
resources.