SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
46
ProvidingAccesstoWindowsTerminalServicesor
CitrixResources
TogiveusersaccesstoanindividualWindowsTerminalServicesorCitrixhost,oraCitrixserver
farm:
1InstallorupdatetheWindowsTerminalServicesagentortheCitrixagentontheConfigureGraphical
TerminalAgentspage.
2DefinearesourceontheAdd/EditResourcepagefortheWindowsTerminalServicesorCitrixhost,or
theCitrixserverfarm.
3CreatearuleontheAdd/EditAccessRulepagereferencingthe
terminal‐serverresource.
4CreateaWorkPlaceshortcutforaccessingtheWindowsTerminalServiceshostorCitrixresourceonthe
Add/EditTerminalShortcutpage.
AuthenticationScenarios
Realmsareusedbytheapplianceforthefollowingkeypurposes:
• Referencingexternalauthenticationservers
• ProvisioningaccessagentstoVPNusers,basedoncommunitymembership
• DeterminingwhichEndPointControlrestrictionsareimposedonusers’devices
• Controllingtheuser’sloginexperienceataWorkPlaceportal
UsingMultipleRealmsvs.aSingleRealm
Ifyourorganizationusesonlyoneauthenticationserver,you’llprobablyneedtoconfigureonlyonerealmin
AMC.Thereareothersituationsinwhichmultiple authenticationserversarerequired:
•Multipleuserrepositories—Ifyourusersarestoredinmultipledirectories,youmustcreateaseparate
realmforeachone.Forexample,if
youremployeesarestoredonanLDAPserver,whileyourbusiness
partnersarestoredonanActiveDirectoryserver,createaseparaterealmforeachdirectoryserver.
•Chainedauthentication—Forincreasedsecurity,youcanrequireuserstoauthenticatetoasinglerealm
usingtwodifferentauthenticationmethods.Forexample,youset
upRADIUSoradigitalcertificateasthe
firstauthenticationmethod,andLDAPorActiveDirectoryasthesecondone.Tomakethelogin
experienceforyourusersaone‐stepprocess,configureAMCsuchthatusersseeonlyonesetof
prompts.
AccessComponentProvisioning
AlloftheuseraccesscomponentsareprovisionedoractivatedthroughtheWorkPlaceportal.
Optionally,youcanmaketheConnectTunnelclientcomponentsavailableforuserstodownloadandinstallfrom
anothernetworklocation(suchasaWebserver,FTPserver,orfileserver),withoutrequiringthemtologinto
WorkPlace.