EasyManua.ls Logo

SonicWALL SMA - Authentication Scenarios; Access Component Provisioning

SonicWALL SMA
48 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
46
ProvidingAccesstoWindowsTerminalServicesor
CitrixResources
TogiveusersaccesstoanindividualWindowsTerminalServicesorCitrixhost,oraCitrixserver
farm:
1InstallorupdatetheWindowsTerminalServicesagentortheCitrixagentontheConfigureGraphical
TerminalAgentspage.
2DefinearesourceontheAdd/EditResourcepagefortheWindowsTerminalServicesorCitrixhost,or
theCitrixserverfarm.
3CreatearuleontheAdd/EditAccessRulepagereferencingthe
terminalserverresource.
4CreateaWorkPlaceshortcutforaccessingtheWindowsTerminalServiceshostorCitrixresourceonthe
Add/EditTerminalShortcutpage.
AuthenticationScenarios
Realmsareusedbytheapplianceforthefollowingkeypurposes:
Referencingexternalauthenticationservers
ProvisioningaccessagentstoVPNusers,basedoncommunitymembership
DeterminingwhichEndPointControlrestrictionsareimposedonusers’devices
ControllingtheusersloginexperienceataWorkPlaceportal
UsingMultipleRealmsvs.aSingleRealm
Ifyourorganizationusesonlyoneauthenticationserver,you’llprobablyneedtoconfigureonlyonerealmin
AMC.Thereareothersituationsinwhichmultiple authenticationserversarerequired:
•Multipleuserrepositories—Ifyourusersarestoredinmultipledirectories,youmustcreateaseparate
realmforeachone.Forexample,if
youremployeesarestoredonanLDAPserver,whileyourbusiness
partnersarestoredonanActiveDirectoryserver,createaseparaterealmforeachdirectoryserver.
•Chainedauthentication—Forincreasedsecurity,youcanrequireuserstoauthenticatetoasinglerealm
usingtwodifferentauthenticationmethods.Forexample,youset
upRADIUSoradigitalcertificateasthe
firstauthenticationmethod,andLDAPorActiveDirectoryasthesecondone.Tomakethelogin
experienceforyourusersaonestepprocess,configureAMCsuchthatusersseeonlyonesetof
prompts.
AccessComponentProvisioning
AlloftheuseraccesscomponentsareprovisionedoractivatedthroughtheWorkPlaceportal.
Optionally,youcanmaketheConnectTunnelclientcomponentsavailableforuserstodownloadandinstallfrom
anothernetworklocation(suchasaWebserver,FTPserver,orfileserver),withoutrequiringthemtologinto
WorkPlace.

Table of Contents

Related product manuals