EasyManua.ls Logo

SonicWALL SMA - Authentication; Resources; Users and Groups

SonicWALL SMA
48 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
AboutSonicWallSMAConnectTunnel
7
SingleSignOnonpage10
SharingConfigurationDataonpage10
RolebasedAdministrationonpage10
SystemMonitoringandLoggingonpage10
Resources
TheSonicWallSMAappliancemanagesawidevarietyofcorporateresourcesinthreemaincategories:
•Webresources—ApplicationsorservicesthatrunovertheHTTPorHTTPSprotocolsuchasMicrosoft
OutlookWebAccess
Client/serverresources—EnterpriseapplicationsthatrunoverTCP /IP,suchasCitrix,andVoiceover
InternetProtocol(VoIP)telephony
applications
•Fileshares—Networkserversorcomputerscontainingsharedfoldersandfiles
Whenspecifyingaresourcetype,keeptheintendedaudienceinmind.Forexample,youcangivebusiness
partnersnarrowaccesstoaWebapplicationbydefiningaURLasaresource(andevenaliasthehostnamefor
anextra
measureofsecurity).
Togiveremoteemployeesbroaderaccess,youcoulddefinethenetworksegmentinwhichtheWebapplication
islocatedasadomain ,IPrange,orsubnetresource.EmployeeswouldthenhaveaccesstoalloftheWeb
resourcesinthatdomain.
UsersandGroups
Auserisanindividual whoneedsaccesstoresourcesonyournetwork,andagroupisacollectionofusers.After
you’vecreatedusersorusergroupsontheappliancethataremappedtoanexternalauthenticationserver,you
canreferencetheminaccesscontrolrulestopermitordeny
themaccesstoresources.Youcanevenform
dynamicgroupsifyouwanttoreferenceauserpopulationthatisn’talreadydefinedintheexternaldirectory.
Authentication
Authenticationistheprocessofverifyingausersidentity.Tomanageuserauthenticationwiththeappliance,
useAMCtodefineoneormoreexternalauthenticationservers(alsoknownasdirectoryserversoruserstores)
thatcontainthecredentialsforyouruserpopulation.Theactualmanagementoftheuserinformationisstill
doneonyourauthenticationservers;theappliancemakesuseofthatinformationtoauthenticateusers.
CreatinganauthenticationrealminAMCalsoinvolvesspecifyinganauthenticationmethod
(username/passwordoronetimepassword,tokenorsmartcard,ordigitalcertificate).
TheSMAappliancesupportsthesedirectoriesandauthenticationmethods:
LDAPwithusername/password
supportsLDAPCertificate
DellDefender
SAMLCASiteMinder
RADIUSPhoneFactorwithusername/passwordortokenbasedauthenticationsuchasSecurIDorSoftID
MicrosoftActiveDirectorywithusername/password,configuredwitheitherasinglerootdomain,orone
ormoresubordinate(child)domains
PublicKeyInfrastructure(PKI)withdigitalcertificate

Table of Contents

Related product manuals