General Information - Celestix E6600 Installation Manual

E series
Table of Contents

Advertisement

General Information

The following deployment notes provide information that qualifies setup processes to understand Remote
Access configuration.
Deployment Assumptions
Information presented in the E Series setup instructions is based on the following:
• The Remote Access with VPN feature has been installed through the web UI.
• Deployment is a single server.
• Network planning for appliance placement is complete.
• Necessary certificates have been acquired for:
▪ IPsec
▪ IP-HTTPS
▪ NLS
• Certificates have not been previously imported to the certificate store.
• Firewall rules have been configured to allow traffic if the DirectAccess server is on an IPv4
network:
▪ Teredo
▪ 6to4
▪ IP-HTTPS
▪ If the appliance only has one configured network adapter, TCP port 62000 must be opened
on the appliance.
Additional firewall configuration details are discussed in the topic
• If using a security group to manage access for clients, the group has been created in AD prior to
running the setup up wizard.
• If customized GPOs will manage settings for clients and servers, they have been created prior to
running the setup wizard.
• AD will be used for DirectAccess authentication and authorization.
• DNS needs to resolve to either the public host name of the DirectAccess entry point, or the NAT
device for the DirectAccess server.
Requirement Checklist
The following items will be required to set up Remote Access. Plan ahead so that items are available
when needed to complete configuration.
• Domain controller – DirectAccess requires Windows Server 2003 or higher.
• IP address – one or two address have been reserved.
• Public address – usually an FQDN that clients will use to connect to the network.
• DirectAccess clients – must be Windows clients that are domain joined. Supported options:
▪ 8 Enterprise and higher
▪ 7 (Ultimate, Enterprise)
• SSL certificate – an IPsec root certificate is required for Windows 7 DirectAccess client
connections, and is a best practice for Windows 8.
• Email account – an account will be required to receive diagnostic reports for client access trouble
shooting.
Additional Configuration Notes
The notes below discuss options that may apply to some deployments. They exceed the scope of these
instructions, but may be helpful to consider when planning.
• DirectAccess
30
Firewall Ports
Reference.
E Series Installation Guide

Advertisement

Table of Contents
loading

Table of Contents