Table of Contents

Advertisement

Step
6.
Configuring a user group
7.
Viewing user information
8.
Performing basic configurations for the SSL
VPN domain
9.
Configuring authentication policies
10. Configuring a security policy
11. Customizing the SSL VPN user interface

Configuring PKI

Before configuring the SSL VPN service, configure a PKI domain and request certificates. The certificates
are used to authenticate the identity of the SSL VPN gateway, preventing the administrator or users from
logging in to an illegal SSL VPN gateway. For more information about PKI and PKI configurations at the
CLI, see "Configuring PKI."
The system supports the following PKI certificate request modes:
Manual—In manual mode, you need to manually retrieve a CA certificate, generate a local RSA
key pair, and submit a local certificate request for an entity.
Auto—In auto mode, an entity automatically requests a certificate through the SCEP when it has no
local certificate or the present certificate is about to expire.
Remarks
Required.
Configure a user group, add local users to the user group,
and select the resource groups that the user group can
access.
By default, a user group named Guests exists, and no users
and resource groups are assigned for it.
IMPORTANT:
You can also add a local user to existing user groups when
creating the local user.
Optional.
View the online user information and the history user
information, and log out online users.
Optional.
Configure the basic domain policy, caching policy, bulletin
information for an SSL VPN domain.
Optional.
Configure authentication methods and authentication
parameters for an SSL VPN domain.
IMPORTANT:
Local authentication is always enabled. To use other
authentication methods, you must manually enable them.
Optional.
Configure the check items and protected resources for a
security policy. Only user hosts that pass the security
policy's check can access the configured resources.
IMPORTANT:
To perform security check for user hosts, you must also enable
security check in the domain policy.
Optional.
Customize service interfaces for SSL VPN users.
360

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents