SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
26
Thenextstepistoputitalltogether,usingtheVPNbuildingblocksyoucreated,andconfiguretwo
communities,anemployee communityandapartnercommunity.Thestepsforconfiguringeithercommunity
arethesame:
Throughouttheseprocedures,remembertoclickPendingChangesintheupper‐rightcornerinAMC,
andthen
clickApplyChangestosaveyourconfigurationchanges.
Topics:
• EstablishinganAuthenticationRealmonpage26
• IdentifyingUsersonpage30
• AddingResourcesonpage31
• CreatingZonesofTrustonpage31
EstablishinganAuthenticationRealm
Toauthenticateyourusers,youmustfirstdefineanauthenticationrealm,whichisthecombinationofan
existingcompanydirectoryandanauthenticationmethod.
VPNbuildingblocksandtheirdescriptions
VPNBuildingBlocks Description
Createanauthenticationrealm SetupaMicrosoftActiveDirectory(AD)authenticationserver.
SeeEstablishinganAuthenticationRealmonpage
26.
Identifyusers AddafewtestuserswithnamesthatmatchonesonyourADserver.Forthis
testscenario,wewillidentifytwoofthemasemployees,andtwoofthemas
partners.
SeeIdentifyingUsersonpage30.
Addresources Definejustafewresources.
SeeAddingResourcesonpage31
.
EndPointControl CreatetwoStandardzonesoftrust:atrustedoneformembersofthe
Employeescommunity,andalesstrustedoneforPartners.Also,createa
quarantinezonefordevicesthatdon’tfitintoeithercommunity.
CreateWorkPlacestylesand
layouts
ChangehowWorkPlacelooksonaper‐communitybasis.
Thoughoptional,
thisproducesamorepolishedandcustomizedlook.Wewi llmodifythe
defaultstyleandlayoutanduseitfortheemployeescommunity,andthen
createadifferentlookforthepartnercommunity.
SeeCustomizingWorkPlaceonpage33.
Settingupcommunitiesandtheirdescription
SettingUpCommunities Description
Members Identifythe
membersforeachcommunity.
Accessmethods Definewhataccessmethodsareavailable.
EndPointControl Createzonesoftrust:atrustedoneformembersoftheEmployees
community,andalesstrustedoneforPartners.
WorkPlaceappearance UsedifferentWorkPlacestylesandlayoutsforthetwocommunities.
Accesscontrolrule Createrulesforwhatresources
canbeaccessedbywhichusers.
SeeAccessControlListsonpage39.