18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring client address pools<br />

Terminate the desired VPN<br />

association in the virtual<br />

burb<br />

Configuring client<br />

address pools<br />

13-18 Configuring Virtual Private Networks<br />

5. Select Policy Configuration -> Rules and define the rules that allow<br />

access to and from the virtual burb.<br />

Note: Be sure to add any rules you create to the active proxy rule group.<br />

The virtual burb should be specified as either the source or destination<br />

burb, depending on the type <strong>of</strong> rule being defined.<br />

6. Terminate the desired VPN security association(s) in the virtual burb.<br />

See “Configuring VPN Security Associations” on page 13-51 for<br />

information on creating or modifying a VPN association.<br />

Client address pools are used to simplify the management <strong>of</strong> VPN<br />

clients. They do so by having the <strong>Sidewinder</strong> <strong>G2</strong> manage certain<br />

configuration details on behalf <strong>of</strong> the client. All the client needs is:<br />

Client s<strong>of</strong>tware that supports ISAKMP mode-config exchange<br />

Authorization information (a client certificate, a password, etc.)<br />

The address <strong>of</strong> the <strong>Sidewinder</strong> <strong>G2</strong><br />

Here is how it works: you create a "pool" <strong>of</strong> IP addresses that will be<br />

used by remote clients when they attempt to make a VPN connection.<br />

When a client attempts a connection, the <strong>Sidewinder</strong> <strong>G2</strong> assigns it one<br />

<strong>of</strong> the IP addresses available in the address pool. The <strong>Sidewinder</strong> <strong>G2</strong><br />

also negotiates with the client to determine other VPN requirements,<br />

such as which DNS and/or WINS servers will be made available to the<br />

client. If the negotiation is successful, the client is connected and the<br />

VPN association is established.<br />

Note: To date, not all VPN client s<strong>of</strong>tware supports the negotiation <strong>of</strong> every client address<br />

pool parameter. Be sure to verify that your client(s) support the necessary features.<br />

The number <strong>of</strong> IP addresses available in the client address pool is<br />

dictated by the value defined in the Virtual Subnet field. Even though<br />

the client may have a fixed IP address, the address used within the<br />

VPN association is the address assigned to it from the address pool.<br />

The address pool works for both fixed and dynamic clients. This<br />

means that in the scenarios described at the end <strong>of</strong> this chapter,<br />

address pools could be used in scenario 2 or scenario 3.<br />

You can create multiple client address pools if desired. Grouping VPN<br />

clients into distinct pools allows you to limit the resources the clients<br />

in each group can access.<br />

The following sections explain how to configure client address pools.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!