EasyManua.ls Logo

Stormshield SN series - SSL Server; Conditions of Use for Internet Access; Advanced Properties

Stormshield SN series
448 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
SSL server
Certificate (private
key)
By default, the CA that the firewall’s authentication module uses is the firewall’s own
CA, and the name associated with this CA is the product’s serial number.
Thus, when a user attempts to contact the firewall other than by its serial number, it
will receive a warning message indicating incoherence between what the user is trying
to contact and the certificate it is receiving.
By clicking on the icon , the CA configuration screen will appear (server certificate)
and you can select a CA that was imported earlier.
Users are authenticated via the captive portal by default, through an SSL/TLS access
that uses a certificate signed by two authorities not recognized by the browsers. It is
therefore necessary to deploy these certificate authorities used by a GPO on users’
browsers. These authorities are by default the NETASQ CA and Stormshield CA,
available from the following links:
l http://pki.stormshieldcs.eu/netasq/root.crt.
l http://pki.stormshieldcs.eu/products/root.crt.
For further detail, please refer to the chapter Welcome > User awareness, under Initial
connection to the appliance.
Conditions of use for Internet access
Conditions of use for internet access can be displayed for the user. He will need to select the
checkbox indicating his agreement to the terms before being able to authenticate.
This option can be enabled in the "Available methods" tab (Guest method) or "Captive portal
profiles" tab (other methods). You can customize these conditions by entering, for example, the
name of your company.
Select the conditions of use for internet access in HTML format Imports your version in HTML.
Select the conditions of use for internet access in PDF format Imports your version in PDF.
Advanced properties
Interrupt connections
once the
authentication period
expires
As soon as the authentication duration expires, connections will be interrupted, even
if the user is in the middle of a download.
Proxy configuration file
(.pac)
This field allows sending to the firewall the .pac file, which represents the proxy’s
automatic configuration file (Proxy Auto-Config), to be distributed. Users can retrieve
.pac files or check their contents by clicking on the button to the right of the field.
Users can indicate in their web browsers the automatic configuration script located at
https://if_firewall>/config/wpad.dat.
Captive portal
Hide the header (logo) This option makes it possible to hide the Stormshield Network banner (this is the
Stormshield logo by default) when the user authenticates on the captive portal, for
confidentiality reasons.
Select a logo to display
(800x50 px)
You can select the image that will appear in the captive portal’s header. The format
of the image has to be 800 x 50 px by default.
Page 56/448 sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
SNS - USER CONFIGURATION MANUAL V.3
AUTHENTICATION

Table of Contents