Chapter 4
4 - 28
5. (Optional) To have only the traffic targeted at a specified address
space go through the SSL VPN Webifyer, select the Use split
tunneling option. All of the remote user’s other Internet activity is
handled by the user’s ISP.
For example, you might want to enable this option if a company
does not want a remote user’s personal Internet activity to be
channeled through the company network. Alternatively, you might
want to disable this option if your company’s security policy is to
perform a virus scan on all files a remote user accesses.
6. Click the Update button to update the screen.
7. If you selected the split tunneling option, the LAN Address Space
box appears. Enter a space-separated list of addresses or
address/mask pairs describing the target LAN to use for split
tunneling.
Only the traffic to these addresses and network segments goes
through the SSL VPN.
8. To have the SSL VPN client work through a proxy server on the
target network, select the Client proxy settings option.
Note: The Client Proxy Settings option requires Internet Explorer
5.0 or later to be installed on the user’s computer or access point.
9. Click the Update button to update the screen.
10. If you selected the Client proxy settings option, do the following:
a) In the Address box and the Port box, enter the IP address and
port number of the proxy server you want the SSL VPN client to
use to connect to the Internet.
b) To use the proxy server for all local (Intranet) addresses, select
the Bypass proxy for local addresses option.
c) In the Proxy exclusion list box, enter the Web addresses that do
not need to be accessed through the proxy server. You can use
wild cards to match domain and host names or addresses. For
example:
www.*.com; 128.*, 240.*, *. mygroup.*, *x*
11. (Optional) To prevent all network configuration changes on the
client computer during an SSL VPN client session, select the
Prohibit routing table changes during SSL VPN connection
option, further down the screen.
When this option is selected, the SSL VPN connection terminates if
there are any network configuration changes made on the client
computer. For example, if a user has an SSL VPN connection
established, and then starts a new dial-up connection or inserts a
new network card, the SSL VPN connection terminates. This option
is useful for security reasons.
Summary of Contents for FirePass
Page 1: ...FirePassTM Server Administrator Guide version 4 0 MAN 0081 00 ...
Page 2: ......
Page 4: ...ii ...
Page 5: ...Table of Contents ...
Page 6: ......
Page 12: ......
Page 18: ...Chapter 1 1 6 ...
Page 20: ......
Page 44: ...Chapter 2 2 24 ...
Page 46: ......
Page 82: ...Chapter 3 3 36 ...
Page 84: ......
Page 124: ......
Page 156: ...Chapter 5 5 32 ...
Page 158: ......
Page 168: ......
Page 177: ...Index ...
Page 178: ......