32
E Series Installation Guide
ii.
Public address
– enter the address that external clients will use to connect to the
network.
Note: While using an IP address is supported, the FQDN is a best practice.
For example:
da.example.com
b.
Advanced
– define client parameters and assign the appliance network adapter that
DirectAccess service will use.
i. Installation type
– select the DirectAccess functionality to deploy:
•
Full DirectAccess installation
– bidirectional tunnels for remote client access
and management.
•
Client management only
– configure tunnel for remote client management.
ii.
Client Group
– designate an AD security group that will manage devices that
connect through DirectAccess; leave blank to include all remote devices.
iii. Network interfaces
– select interfaces for DirectAccess traffic.
1.
Internal
– specify the internal, or LAN, network adapter in the drop menu.
2.
Internet
– optional; if two adapters are used, specify the Internet, or WAN,
network adapter in the drop menu.
iv. IP-HTTPS certificate
– if a third-party certificate will be used to bind the Internet
network adapter, navigate to and select it. If it needs to be imported first, complete
the following:
a. Click the
Import
button.
b.
Certificate Import
– navigate to and select the certificate that will be used for
authentication.
c.
Password
– enter the certificate passphrase.
d. Click the
Import
button.
e. The imported certificate should display in the
Certificate
field. If not, use the
drop menu to select it.
c.
GPO and NLS
i. Group Policy Object (GPO)
– leave fields blank to configure the default options,
otherwise designate predefined AD policy groups that will manage settings for
devices and servers.
1.
Client GPO
– specify the name for the AD policy that will manage client
access.
2.
Server GPO
– specify the name for the AD policy that will manage access to
the DirectAccess server.
ii. Network Location Server
– the NLS server will be installed on the appliance unless
an external server is designated.
1.
NLS Certificate
– if an SSL certificate will be used, navigate to and select it. If
it needs to be imported first, complete the following:
a. Click the
Import
button.
b.
Certificate Import
– navigate to and select the certificate that will be
used for authentication.
c.
Password
– enter the certificate passphrase.
d. Click the
Import
button.
e. The imported certificate should display in the
Certificate
field. If not,
use the drop menu to select it.
2.
NLS URL
– if an external NLS server is deployed, enter the HTTPS URL.
d.
Client Settings
i.
Connection Name
– create a name for the network connection that end users will
recognize.
ii.
Support Email
– enter the email account that will receive diagnostic reports created
by the
DirectAccess Diagnostics
tool.
iii.
Allow local name resolution
– select to allow users to temporarily disconnect the
intranet connection and use local DNS servers for Internet traffic.
Notes:
•
Force tunneling must be disabled to employ this feature.
Summary of Contents for E6600
Page 1: ...Security Simplified Celestix E Series Installation Guide E6600 Security Appliance ...
Page 7: ...6 E Series Installation Guide ...
Page 8: ...7 E Series Installation Guide ...
Page 9: ...8 E Series Installation Guide ...
Page 10: ...9 E Series Installation Guide Illustration 2 Appliance Illustrations with Delineated Features ...