EasyManuals Logo

SonicWALL SMA User Manual

SonicWALL SMA
48 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #9 background imageLoading...
Page #9 background image
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
AboutSonicWallSMAConnectTunnel
9
EndPointControl(EPC)
TraditionalVPNsolutionstypicallyprovideaccessonlyfromtherelativesafetyofanITmanageddevice.Inthat
environment,themajorsecurityconcernisunauthorizednetworkaccess.BecauseanSSLVPNenablesaccess
fromanyWebenabledsystem,itmaybringtheadditionalriskofcomputersinuntrustedenvironments,suchas
akioskatanairportorhotel,oranemployeeownedcomputer.
Theappliance’sEPCconfigurationoptionsgiveyougranularcontroloverVPNaccessusingprofilesandzonesto
protectsensitivedataandensurethatyournetworkisnotcompromised:
Adeviceprofileisasetofattributesthatcharacterize
thedevicerequestingtheconnection,suchasa
Windowsdomainname,thepresenceofacertainsoftwareprogram,aregistryentry,orotherunique
characteristics.
AnapplicationaccesszoneisasetofattributesusedtoestablishatrustrelationshipwithaclientiOSor
Androiddevice.
AnEndPointControl
zoneclassifiesaconnectionrequestbasedonthepresenceorabsenceofadevice
profile.Thezoneinwhichadeviceisthenplacedcontrolstheprovisioningofdataprotection
componentsandcanbeusedtodeterminewhichresourcesareavailable.Adevicecanbeplacedina
Standardzone,
aQuarantinezone(withinstructionsoninstallingtherequiredsecurityprograms),orina
Denyzone,wheretheuserisdeniedaccesstothenetwork.
SSLandEncryption
TheSonicWallSMAapplianceencryptsinformationusingtheSecureSocketsLayer(SSL)protocol.SSLprotocolis
anauthenticationandencryptionprotocolthatusesakeyexchangemethodtoestablishasecureenvironment
inwhichalldataexchangedisencryptedtoprotectitfromeavesdroppingandalteration.
TheapplianceusesSSLce rtificates
tovalidatetheappliance’sidentitytoconnectingusers,andtoprovidea
publickeytosecureinformationthattheclientcomputersendstotheserver.Theappliancerequiresa
minimumoftwoSSLcertificates:
Theapplianceservicesuseacertificatetosecureusertraffic.
TheApplianceManagementConsole(AMC)uses
acertificatetosecuremanagementtraffic.
Therearetwotypesofcertificates:selfsignedand commercial.Withaselfsigned SSLcertificate,theappliance
identifiesitselfwithacertificatethathasnotbeensignedbyacommercialCA,andtheassociatedprivatekey
dataisencryptedusingapassword.AMC uses
aselfsignedcertificate.
Aselfsignedcertificatecanalsobeawi ldcardcertificate,allowingittobeusedbymultipleserverswhichshare
thesameIPaddressandcertificate,buthavedifferentFQDNs.Forexample,awildcardcertificatesuchas
*.company.comcouldbeusedforiPhoneaccessatand
forVPNaccessatvpn.company.com.
YoucanalsoconfigureanauthenticationservertotrustanintermediateCA.Forexample,youcouldcreatea
rootcertificatesigningauthorityonasystemthatisnotconnectedtothecorporatenetwork.Youcanthenissue
asetoftrustedintermediatesigningauthoritycertificatesto
bedeployedinvarioussectorsofthenetwork
(oftenbydepartmentororganizationalunit).
AlthoughaselfsignedSSLcertificateissecure,youmaywanttosecureusertr afficwithacertificatefroma
commercialcertificateauthority(CA)suchasVeriSign.
Whendecidingwhichtype ofcertificatetousefor
theservers,considerwhowi llbeconnectingtotheappliance
andhowtheywilluseresourcesonyournetwork:
IfbusinesspartnersareconnectingtoWebresourcesthroughtheappliance,theywilllikelywantsome
assuranceofyouridentitybeforeperformingatransactionorprovidingconfidentialinformation.Inthis
case,you
wouldprobablywanttoobtainacertificatefromacommercialCAfortheappliance.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the SonicWALL SMA and is the answer not in the manual?

SonicWALL SMA Specifications

General IconGeneral
Firewall ThroughputVaries by model
VPN ThroughputVaries by model
Max Concurrent ConnectionsVaries by model
New Connections Per SecondVaries by model
SSL VPN ThroughputVaries by model
SSL Inspection ThroughputVaries by model
IPS ThroughputVaries by model
Anti-Malware ThroughputVaries by model
Interface OptionsMultiple Gigabit Ethernet ports, SFP+ ports
Form FactorVaries by model
Power SupplyVaries by model
Authentication MethodsVaries by model
High AvailabilityActive/Passive, Active/Active
User CapacityVaries by model

Related product manuals