SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
32
forPartners.We’llalsosetupaQuarantinezoneforusers(employeesorpartners)whosedevicesfailtomatch
theprofilesthatwespecify.
Creatingazoneissimplyawayofsettingoneormoreconditionsthatusersmustmeetbeforetheyaregranted
secure,remoteaccesstoresources.In
ourexample,theuserwillbeclassifiedintotheTrustedzoneifacertain
antivirusprogramisrunning(NortonAntiVirusisusedinthisex ample,butyoucansubstituteanotherprogram).
Iftheprogramisnotrunning,theuserisclassifiedintotheUntrustedzone.
Theconditionsyousetin
arealdeploymentwillofcoursebedifferent—thisisjustademonstrationofhowEPC
works.
Topics:
• CreatingaStandard ZoneforTrustedUsersonpage32
• CreatingaStandard ZoneforPartnersonpage32
• CreatingaQuarantineZoneforUntrustedUsersonpage33
CreatingaStandardZoneforTrustedUsers
TocreateaStandardzonenamedTrustedforemployees:
1FromthemainnavigationmenuinAMC,clickEndPointControl.
2IfthelinknexttoEndPointControlisDisabled,clickthelinkandselecttheEnableEndPointControl
checkboxontheConfigureGeneralApplianceOptionspage.
3 ClickNew,andthenselectStandardzonefromthemenu.The
ZoneDefinition‐StandardZonepage
appears.
4IntheNamefield,typeTrusted.
5IntheAllProfileslist,selectthecheckboxnexttoWindowsantivirus,andthenclicktherightarrows(>>)
toaddittotheInUselist.Toseetheattributesinthisbuilt‐inprofile,clickits
name.
6TheclientdevicewillbecheckedatlogintoseeifitisrunningeitherNortonAntivirusorMacAfee
VirusScan.Ifyouwantthischecktoreoccurduringagivensession,settheintervalinminutesinthe
RecurringEPCarea.
7Whenyouarefinishedconfiguringthezone,clickSave.
TheStandardzonenamedTrustedisnow
displayedinthelistofEndPointControlzones.Tomatchthisprofile,auser ’sdevicemustberunningthe
securityprogramsyouspecifiedinStep5.
Inthisex ample,wewillclassifydevicesthatdonotmatchtheStandardzonewecreated
intoaQuarantinezone
namedUntrusted;seeCreatingaQuarantineZoneforUntrustedUsersonpage33
CreatingaStandardZoneforPartners
TocreateaStandardzonenamedPartnerzoneforpartners:
1FromthemainnavigationmenuinAMC,clickEndPointControl.
2 ClickNew,andthenselectStandardzonefromthemenu.
3IntheNamefield,typePartner zone.
4Tocreateadeviceprofile,clickNew,andthenselectaplatformfromtheshortcutmenu(forexample,
MicrosoftWindows).
5Enteraname
forthedeviceprofileintheNamefield.Forexample,Symantec AV.