SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
AboutSonicWallSMAConnectTunnel
7
• SingleSign‐Ononpage10
• SharingConfigurationDataonpage10
• Role‐basedAdministrationonpage10
• SystemMonitoringandLoggingonpage10
Resources
TheSonicWallSMAappliancemanagesawidevarietyofcorporateresourcesinthreemaincategories:
•Webresources—ApplicationsorservicesthatrunovertheHTTPorHTTPSprotocolsuchasMicrosoft
OutlookWebAccess
• Client/serverresources—EnterpriseapplicationsthatrunoverTCP /IP,suchasCitrix,andVoiceover
InternetProtocol(VoIP)telephony
applications
•Fileshares—Networkserversorcomputerscontainingsharedfoldersandfiles
Whenspecifyingaresourcetype,keeptheintendedaudienceinmind.Forexample,youcangivebusiness
partnersnarrowaccesstoaWebapplicationbydefiningaURLasaresource(andevenaliasthehostnamefor
anextra
measureofsecurity).
Togiveremoteemployeesbroaderaccess,youcoulddefinethenetworksegmentinwhichtheWebapplication
islocatedasadomain ,IPrange,orsubnetresource.EmployeeswouldthenhaveaccesstoalloftheWeb
resourcesinthatdomain.
UsersandGroups
Auserisanindividual whoneedsaccesstoresourcesonyournetwork,andagroupisacollectionofusers.After
you’vecreatedusersorusergroupsontheappliancethataremappedtoanexternalauthenticationserver,you
canreferencetheminaccesscontrolrulestopermitordeny
themaccesstoresources.Youcanevenform
dynamicgroupsifyouwanttoreferenceauserpopulationthatisn’talreadydefinedintheexternaldirectory.
Authentication
Authenticationistheprocessofverifyingauser’sidentity.Tomanageuserauthenticationwiththeappliance,
useAMCtodefineoneormoreexternalauthenticationservers(alsoknownasdirectoryserversoruserstores)
thatcontainthecredentialsforyouruserpopulation.Theactualmanagementoftheuserinformationisstill
doneonyourauthenticationservers;theappliancemakesuseofthatinformationtoauthenticateusers.
CreatinganauthenticationrealminAMCalsoinvolvesspecifyinganauthenticationmethod
(username/passwordorone‐timepassword,tokenorsmartcard,ordigitalcertificate).
TheSMAappliancesupportsthesedirectoriesandauthenticationmethods:
• LDAPwithusername/password
supportsLDAPCertificate
• DellDefender
• SAMLCASiteMinder
• RADIUSPhoneFactorwithusername/passwordortoken‐basedauthenticationsuchasSecurIDorSoftID
• MicrosoftActiveDirectorywithusername/password,configuredwitheitherasinglerootdomain,orone
ormoresubordinate(child)domains
• PublicKeyInfrastructure(PKI)withdigitalcertificate