SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
CommonVPNConfigurations
47
Useraccessagentsaredeployedonaper‐communitybasis.Whenconfiguringausercommunity,youcan
specifywhichaccessmethodswillbeavailabletocommunitymemberstoconnecttoresourcesonyour
network.
WhenauserlogsintoWorkPlaceforthefirsttime,WorkPlaceautomaticallyprovisionsandinstallsthe
appropriateuseraccessagentbasedontheuser’scommunitysettings.Theagentthatisdeployedwillbe
installedontheuser’scomputer;onsubsequentconnectionsfromthesamecomputerwiththesameWeb
browser,thatsameagentisautomaticallydeployed.
Topics:
• DeployingtheSameAgentstoAllUsersonpage47
• DeployingDifferentAgentstoDifferentUsersonpage47
DeployingtheSameAgentstoAllUsers
WhenyoucreateanauthenticationrealminAMC,adefaultcommunityassociatedwiththerealmisalso
automaticallycreated.This singlecommunitymaybesufficientifyouhaveahomogenousgroupofuserswhose
resourceneedsandaccessmethodsareidentical.
Toconfigureasinglecommunity:
1CreatearealmontheGeneralsectionoftheConfigureRealmpagethatref erencesanexternal
authenticationserver.AMCautomaticallycreatesadefaultcommunitythatisreferencedbytherealm.
Thedefaultcommunitysettingsareglobalandapplytoanyrealmsthatreferenceit.
2Configurethecommunitybyselectingtheusers
orgroupswhobelongtoit,theaccessmethodsthey ’ll
usetoconnect totheVPN,andoptionallyanyEndPointControloptions.
Ifyouhaveadiversegroupofremoteusers,you’llprobablywanttocreatemultiplecommunities.
DeployingDifferentAgentstoDifferentUsers
Multiplecommunitiesgiveyoutheflexibilitytoprovisiondifferentaccessagentstodifferentpopulationsof
users,andtodeploydifferentEndPointControlconfigurations.Evenifyourusersarestoredonasingleexternal
authenticationserver,youmaywanttosegmentthembyfunctioninyourorganization,bythetypesof
resourcestowhichtheyneedaccess,orforsecurityreasons.
Forexample,youmaywanttocreateacommunityforthoseemployeeswhouseIT‐managedlaptopsforremote
access,andprovisionthemwiththeConnectTunnelclienttoallowthemextensiveaccesstoyournetwork
resources.Foryourbusinesspartners,
youmaywanttocreateacommunitythatrestrictsthemtoWebaccess
andassignsthemtoanEndPointControlzonethatprovisionsadataprotectiontooltoremoveallsessiondata
aftertheylogoff.
TheconfigurationstepsinvolvedincreatingmultiplecommunitiesaredescribedinDeploymentScenario:
RemoteAccessforEmployeesandPartnersonpage25.