User Guide
137
Configuring the Firebox for Mobile User VPN
From the
Remote User Setup
dialog box:
1
Click the
PPTP
tab.
2
Click
Add
.
3
Use the
Choose Type
drop list to select either a host or network.
You can configure up to 50 addresses. If you select a network address, Remote User PPTP will
use the first 50 addresses in the subnet.
4
In the
Value
field, enter the host or network address in slash notation. Click
OK
.
Enter unused IP addresses that the Firebox can dynamically assign to clients during Remote
User PPTP sessions. Selected addresses must not appear in the Blocked Sites list. The IP
address appears in the list of addresses available to remote clients.
5
Repeat the add process until you have configured all addresses for use with
Remote User PPTP.
Rules for valid Remote User PPTP addresses
• Addresses that have host routes are invalid
• Traffic routed through the default gateway does not receive proxy ARP
treatment
• Addresses whose packets would be routed through the External interface (but
not through the default gateway) are invalid
• Addresses in networks to which you have routes are invalid (except those that
are routed through default route)
• Any other packets are allowed and handled by proxy ARP
Configuring the Firebox for Mobile User VPN
Mobile User VPN requires careful configuration of both the Firebox and the remote
client computers. However, unlike Remote User PPTP, the Firebox administrator
retains more control over the client configuration through an end-user configuration
file. Configuring the Firebox for Mobile User VPN requires the following steps:
• Obtain a license key from WatchGuard
• Add user names to the built-in Firebox group ipsec_users
• Enter the IPSec license key into the Firebox configuration file
• Verify WINS and DNS server settings
• Use Policy Manager to simultaneously configure the Firebox and create end-
user configuration files
• Configure service properties using ipsec_users
• Distribute the end-user configuration files along with the RUVPN client
software and documentation
Purchasing a Mobile User VPN license
WatchGuard Mobile User VPN is an optional feature of the WatchGuard Firebox
System. Although the administrative tools to configure Mobile User VPN are
Summary of Contents for Firebox FireboxTM System 4.6
Page 1: ...WatchGuard Firebox System User Guide Firebox System 4 6 ...
Page 16: ...6 ...
Page 20: ...LiveSecurity broadcasts 10 ...
Page 44: ...LiveSecurity Event Processor 34 ...
Page 52: ...Defining a Firebox as a DHCP server 42 ...
Page 68: ...Service precedence 58 ...
Page 78: ...Configuring a service for incoming static NAT 68 ...
Page 92: ...Establishing an OOB connection 82 ...
Page 94: ...84 ...
Page 112: ...HostWatch 102 ...
Page 118: ...Working with log files 108 ...
Page 130: ...120 ...
Page 158: ...Configuring debugging options 148 ...