06.03.2013 Views

configure Nokia Mobile VPN

configure Nokia Mobile VPN

configure Nokia Mobile VPN

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong><br />

How to Configure <strong>Nokia</strong><br />

<strong>Mobile</strong> <strong>VPN</strong><br />

For Check Point NGX with Challenge-<br />

Response Authentication


Table of Contents<br />

Introduction...................................................................................................................................................................................... 3<br />

Configuring remote client access using challenge-response authentication............................................................................ 4<br />

General settings............................................................................................................................................................................ 4<br />

Configure a new user group and a new user ............................................................................................................................ 5<br />

Configure a <strong>VPN</strong> remote-access community.............................................................................................................................. 9<br />

Export INTERNAL_CA certificate .................................................................................................................................................11<br />

Configure <strong>VPN</strong> remote-access firewall rules............................................................................................................................13<br />

Configuring Office Mode ............................................................................................................................................................16<br />

Policy creation with the Policy Tool using exported CA certificate...........................................................................................21


Introduction<br />

This best-practices document describes how to <strong>configure</strong> <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client manually (without a separate device<br />

management product) using a challenge-response authentication method in the Check Point NGX R65 environments.<br />

For more details on how to use <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client, error code documents, and the policy format document, please<br />

go to http://www.nokiaforbusiness.com/ > Security products > <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> > Resources.<br />

The assumption is that Check Point NGX, Check Point SmartDashboard, and <strong>Mobile</strong> <strong>VPN</strong> Client have been installed, and<br />

all post-installation tasks have been completed before continuing with the steps listed below. After completing these<br />

steps, remember to save the configurations before exiting the tool.


Configuring remote client access using<br />

challenge-response authentication<br />

General settings<br />

First, the administrator must activate <strong>VPN</strong> and enable <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client-specific features in Check Point NGX.<br />

Start by right-clicking on the gateway object and click Edit. The gateway’s General Properties dialog box will open.<br />

Under Check Point Products, place a check mark on the <strong>VPN</strong> item. Click OK to close the dialog.


Click on the Policy menu and select Global Properties; the Global Properties dialog will open.<br />

In the Global Properties dialog, navigate to the Remote Access -> <strong>VPN</strong> Basic item in the tree pane. Make sure that<br />

”Support Legacy Authentication for SC (hybrid mode)” and ”Support remote access <strong>VPN</strong> using <strong>Nokia</strong> clients” are<br />

enabled. Click OK to close the dialog.<br />

Configure a new user group and a new user<br />

The next task is to create a new user group and add a user to that group.


Create a new user group by going to User Groups and selecting New Group.<br />

Give a name to the new group and press OK.


Go to the Users tab. Right-click on the Users icon and select New User and then Default.<br />

In the Log-in Name text box, enter a log-in name for the new user.<br />

Move to the Groups tab. Select the Cr_users group and click Add to bring it to the Belongs to Groups list.


Move to the Authentication tab. From the Authentication Scheme list, select Check Point Password.<br />

Move to the Encryption tab. Make sure that there is a check mark in the IKE item. Click Edit.<br />

Clear the Public Key if it is enabled. Click OK to close all dialogs.


Configure a <strong>VPN</strong> remote-access community<br />

Now the administrator needs to add the Cr_users group to the RemoteAccess <strong>VPN</strong> community.<br />

Open the Manage menu and select <strong>VPN</strong> Communities.<br />

Select RemoteAccess and click Edit.<br />

Click Participating Gateways and click Add to select the gateway.


Select the gateway and click OK.<br />

Go to the Participant User Groups and click Add.<br />

Select Cr_users and click OK.


Export INTERNAL_CA certificate<br />

A CA certificate is needed by <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client when doing challenge-response authentication.<br />

Open the Manage menu; select Servers and OPSEC.<br />

Select ”internal_ca” and click Edit.<br />

Go to the Local SmartCenter Server tab and click Save As. A dialog will open.


Enter a suitable file name and select the location for saving the internal CA certificate. This file is needed for the <strong>Mobile</strong><br />

<strong>VPN</strong> Client and its policy.


Configure <strong>VPN</strong> remote-access firewall rules<br />

Add and edit a couple of firewall rules. In the screenshot above, a few network objects are already defined but they are<br />

not referred to in the following firewall rule examples. By default, ”Any” is used to describe any network, whether<br />

source or destination.<br />

Here is a sample of some completed firewall rules for <strong>VPN</strong> use. The first and last rules are optional. They are here to<br />

Filter out the clutter of log entries and provide a clean and secure Cleanup that will block any traffic not matching the<br />

second rule. The second rule is the important one.<br />

Edit the Source field of the <strong>VPN</strong> rule by right-clicking it and select Add Users Access.


Select the Cr_users group; make sure the Location is set to ”No restriction.” Click OK to close the dialog.<br />

Right-click the <strong>VPN</strong> field and select Edit Cell.<br />

Select ”Only connections encrypted in specific <strong>VPN</strong> Communities.” Click Add.


Select RemoteAccess and click OK.<br />

Click OK to close the dialog.


Configuring Office Mode<br />

To get an internal address for <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client, Office Mode must be activated in the Check Point gateway.<br />

Follow these steps.<br />

Select Manage from the main menu and click Network Objects.<br />

Select New… -> Network.


In the Network Properties dialog, add a name to the Office Mode IP pool, define the actual IP address for that pool, and<br />

press OK.<br />

To add DNS server address, click New.<br />

Then select “Node” -> “Host…”


Enter the name of the DNS server object and it’s IP address.<br />

This will be handed out to <strong>VPN</strong> client when internal addressing is used, enabling internal network DNS resolution.<br />

Click OK to close the Host Node dialog. Both of the network objects appear in the list.<br />

Click OK to close the Network Objects dialog.<br />

Select the gateway, do a right-click, and select Edit.


From the gateway configuration window, select Remote Access -> Office Mode. Click “Allow Office Mode to all users.”<br />

Then select the Manual office mode method, select the Office Mode pool that was created in the previous step.<br />

Click “Optional Parameters…” button.<br />

Enable Primary DNS Server by placing a check mark there and in the pull-down menu, select the previously created DNS<br />

server host object.


In the IP Lease Duration, enter the amount in minutes that the client internal addresses are valid before they are<br />

renewed. This could be for example 60 minutes.<br />

Click OK to close the dialog IP Pool Optional Parameters dialog..<br />

Click OK to close the Check Point gateway properties dialog.


Policy creation with the Policy Tool using<br />

exported CA certificate<br />

It is time to <strong>configure</strong> the <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client to match the <strong>VPN</strong> policy that was created in Check Point NGX. Start<br />

<strong>Nokia</strong> <strong>VPN</strong> Client Policy Tool and press the Load Template button. Select Check_Point_NGX_R65_crack.pol policy from the<br />

Check Point directory. Then add the correct <strong>VPN</strong> gateway address and get a path to the CA certificate. Make sure that<br />

the Format in the Certificate Authority selection is set to BIN. The identity value field can be left empty.<br />

Export the <strong>VPN</strong> policy by pressing the Generate <strong>VPN</strong> Policy button. Store Check_Point_NGX_R65_crack.vpn to your PC;<br />

consult the <strong>Nokia</strong> <strong>Mobile</strong> <strong>VPN</strong> Client User’s Guide, Chapter 6.1, for details on how to install the given policy file to your<br />

device.


Legal Notice<br />

Reproduction, transfer, distribution or storage of part or all of the contents in this document in any form without the prior written<br />

permission of <strong>Nokia</strong> is prohibited.<br />

<strong>Nokia</strong> and <strong>Nokia</strong> Connecting People are trademarks or registered trademarks of <strong>Nokia</strong> Corporation. Other product and company names<br />

mentioned herein may be trademarks or tradenames of their respective owners.<br />

<strong>Nokia</strong> operates a policy of continuous development. <strong>Nokia</strong> reserves the right to make changes and improvements to any of the<br />

products described in this document without prior notice.<br />

Under no circumstances shall <strong>Nokia</strong> be responsible for any loss of data or income or any special, incidental, consequential or indirect<br />

damages howsoever caused.<br />

The contents of this document are provided “as is”. Except as required by applicable law, no warranties of any kind, either express or<br />

implied, including, but not limited to, the implied warranties of merchantability and fitness for a particular purpose, are made in relation<br />

to the accuracy, reliability or contents of this document. <strong>Nokia</strong> reserves the right to revise this document or withdraw it at any time<br />

without prior notice.<br />

Work together. Smarter.<br />

<strong>Nokia</strong> <strong>Nokia</strong> Inc. Inc. 102 Corporate Park Drive, White Plains, NY 10604 USA<br />

Americas Americas Tel: 1 877 997 9199 • Email: usa@nokiaforbusiness.com<br />

Asia Asia Pacific Pacific Tel: +65 6588 33 64 • Email: asia@nokiaforbusiness.com<br />

Europe Europe France +33 170 708 166 • UK +44 161 601 8908 • Email: europe@nokiaforbusiness.com<br />

Middle Middle Middle East East and and Africa Africa Dubai +971 4 3697600 • Email: mea@nokiaforbusiness.com<br />

www.nokiaforbusiness.com<br />

© 2008 <strong>Nokia</strong>. All rights reserved. <strong>Nokia</strong> and <strong>Nokia</strong> Connecting People are registered trademarks of <strong>Nokia</strong> Corporation. Other trademarks mentioned are the property of their respective owners.<br />

<strong>Nokia</strong> operates a policy of continuous development, therefore, reserves the right to make changes and improvements to any of the products described in this document without prior notice.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!