EasyManua.ls Logo

SonicWALL SMA - Denying Access; Application-Specific Scenarios

SonicWALL SMA
48 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
44
4CreateacommunitythatreferencestheStandardzoneyoucreated,andidentifytheQuarantinezoneas
yourfallbackoption.Connectionrequestsfromdevicesthatdon’tmatchthetrustedprofileare
automaticallyassignedtotheQuarantinezone.
DenyingAccess
Theremaybesituationsinwhichyouwanttodenyaccesstoanemployeeusingadevicethathasan
unacceptableprofile.Forexample,followtheseconfigurationstepstodenyaccesstoanemployeewhologsin
usingadevicethatisrunningGoogleDesktop.
Todenyaccess:
1DefineadeviceprofilewithanattributereferencingtheGoogleDesktopapplication.
2 ReferencethedeviceprofileinaDenyzone.
3 ReferencetheDenyzoneinthecommunityusedbyyouremployees.
4TheappliancedeterminesthatthedeviceisrunningGoogleDesktop,makingitamatchforaDenyzone.
Denyzonesare
alwaysevaluatedfirst:ifGoogleDesktopisrunning,nootherzonesareevaluate d,the
accessrequestisdenied,andtheuserisloggedout.
AccessPolicyScenarios
Accesscontrolrulesdeterminewhatresourcesareavailabletousersorgroups.Rulescanbedefinedbroadlyto
provideaccessfromanyaccessmethod,ordefinednarrowlysothatonlyaspecificaccessmethodispermitted.
VPNconnectionstypicallyinvolvewhatarecalledforwardconnections—theseareinitiatedbyauserto
a
networkresource.Allaccessmethodssupportforwardconnections.However,ifyouarerunningthenetwork
tunnelserviceandyoudeploythenetworktunnelclientstoyourusers,youcanalsocreateaccesscontrolrules
forbidirectionalconnections.
AccesscontrolrulesfortheSecureMobileAccessVPN,bidirectional
connectionsencompassthefollowing:
•ReverseconnectionsfromanetworkresourcetoaVPNusersuchasanSMSserverthatpu shesa
softwareupdatetousers’computers.
•CrossconnectionsusingVoiceoverInternetProtocol(VoIP)applicationsthatenableoneVPNuserto
telephoneanotherVPNuser.Theseconnectionsrequireapairof
accesscontrolrules:oneforthe
forwardconnectionandoneforthereverseconnection.ForinformationonVoIPscenarios,seeProviding
AccesstoVoiceOverIP(VoIP)onpage45.
OthertypesofbidirectionalconnectionsincludeFTPserversthatdownloadfilestooruploadfilesfroma
VPNuser,
andremoteHelpDeskapplications.
ApplicationSpecificScenarios
Herearesomeex amplesofhowtoconfigurethe appliancetopermitremoteuserstoaccesssomecommonly
usedapplicationssuchasMicrosoftOutlookWebAccessandCitrix.
Topics:
ProvidingAccesstoOutlookWebAccess(OWA)onpage45
ProvidingAccesstoVoiceOverIP(VoIP)onpage45

Table of Contents

Related product manuals