SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
44
4CreateacommunitythatreferencestheStandardzoneyoucreated,andidentifytheQuarantinezoneas
yourfallbackoption.Connectionrequestsfromdevicesthatdon’tmatchthetrustedprofileare
automaticallyassignedtotheQuarantinezone.
DenyingAccess
Theremaybesituationsinwhichyouwanttodenyaccesstoanemployeeusingadevicethathasan
unacceptableprofile.Forexample,followtheseconfigurationstepstodenyaccesstoanemployeewhologsin
usingadevicethatisrunningGoogleDesktop.
Todenyaccess:
1DefineadeviceprofilewithanattributereferencingtheGoogleDesktopapplication.
2 ReferencethedeviceprofileinaDenyzone.
3 ReferencetheDenyzoneinthecommunityusedbyyouremployees.
4TheappliancedeterminesthatthedeviceisrunningGoogleDesktop,makingitamatchforaDenyzone.
Denyzonesare
alwaysevaluatedfirst:ifGoogleDesktopisrunning,nootherzonesareevaluate d,the
accessrequestisdenied,andtheuserisloggedout.
AccessPolicyScenarios
Accesscontrolrulesdeterminewhatresourcesareavailabletousersorgroups.Rulescanbedefinedbroadlyto
provideaccessfromanyaccessmethod,ordefinednarrowlysothatonlyaspecificaccessmethodispermitted.
VPNconnectionstypicallyinvolvewhatarecalledforwardconnections—theseareinitiatedbyauserto
a
networkresource.Allaccessmethodssupportforwardconnections.However,ifyouarerunningthenetwork
tunnelserviceandyoudeploythenetworktunnelclientstoyourusers,youcanalsocreateaccesscontrolrules
forbi‐directionalconnections.
AccesscontrolrulesfortheSecureMobileAccessVPN,bi‐directional
connectionsencompassthefollowing:
•ReverseconnectionsfromanetworkresourcetoaVPNusersuchasanSMSserverthatpu shesa
softwareupdatetousers’computers.
•Cross‐connectionsusingVoiceoverInternetProtocol(VoIP)applicationsthatenableoneVPNuserto
telephoneanotherVPNuser.Theseconnectionsrequireapairof
accesscontrolrules:oneforthe
forwardconnectionandoneforthereverseconnection.ForinformationonVoIPscenarios,seeProviding
AccesstoVoiceOverIP(VoIP)onpage45.
• Othertypesofbi‐directionalconnectionsincludeFTPserversthatdownloadfilestooruploadfilesfroma
VPNuser,
andremoteHelpDeskapplications.
Application‐SpecificScenarios
Herearesomeex amplesofhowtoconfigurethe appliancetopermitremoteuserstoaccesssomecommonly
usedapplicationssuchasMicrosoftOutlookWebAccessandCitrix.
Topics:
• ProvidingAccesstoOutlookWebAccess(OWA)onpage45
• ProvidingAccesstoVoiceOverIP(VoIP)onpage45