SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
43
AccesstoaSpecificWebResourceUsinganAlias
Toprovideaccesstoasp ecificWebresource,usinganaliastopreventusersfromseeingitsinternal
hostname:
1DefineaURLresourceontheAdd/EditResourcepage.
2Specifyanaliasfortheresourceinthepage’sAdvancedsection.
3CreatearulereferencingtheURLontheAdd/EditAccessRulepage.
4AddaWebshortcuttoWorkPlaceontheWorkPlaceShortcutspage.
Web‐BasedAccesstoaClient/ServerApplication
ToprovideWebaccesstoaclient/serverapplicationsuchasaCRMsystem:
1DefineanetworkresourceontheAdd/EditResourcepage,referencingtheapplication’s hostnameorIP
address.
2CreatearuleontheAdd/EditAccessRulepagereferencingthenetworkresource.
3ConfiguretheOnDemandandTunnelclient.
4AddaWebshortcutontheWorkPlaceShortcutspage.
EndPointControlScenarios
HerearesomebasicexamplesofhowtodeployEndPointControltoprotec tsensitivedataand ensurethatyour
networkisnotcompromisedwhenaccessedfromdevicesinuntrustedenvironments.
Topics:
• QuarantiningEmployeesonUntrustedSystemsonpage43
• DenyingAccessonpage44
QuarantiningEmployeesonUntrustedSystems
Followtheseconfigurationstepstoquarantineanemployeewhologsinusingadevicethatdoesn’tmatchany
ofyourdeviceprofiles.Theonlyresourcesavailablewillbethosethatyousetup.Youcould,forexample,
displayacustomizedpagewithlinkstoWebresourcesforbringingtheuser’ssystem
intocompliancewithyour
securitypolicies:
ToquarantineanemployeeonUntrustedsystems:
1DefineadeviceprofileontheDeviceProfileDefinitionpagewithanattributereferencinganapplication
orotherattributethatisuniquetoyourorganization.
2ConfigureaStandardzonethatreferencesthedeviceprofileinstep1.
3ConfigureaQuarantinezonethatdisplaysacustomWebpagewithlinkstoresourcesfor
bringinga
user’ssystemintocompliance.