VLAN Policy Examples
Firebox Vclass User Guide
225
fied by the RADIUS system, the Firebox appliance associ-
ates the user (IP address) to the relevant domain. Any
traffic from the user will then be covered by policies that
incorporate that domain.
An example of a user-domain policy in use
As noted previously, the key element in user-domain ten-
ant policies is
user authentication
, which is how traffic per-
taining to a specific tenant is identified. For example:
•
The Vcontroller administrator creates a user-domain
tenant record for “Engineering” domain users that uses
a RADIUS server for user authentication.
•
Policies are created to manage traffic for an external
network, originating from “Engineering.”
•
When one of the tenant users wants to make an
external connection, he or she opens a Web browser
and logs into the Firebox appliance. The user’s IP
address is also noted by the appliance.
•
After the user provides a user name, password, and
domain name (specified in the Tenant entry as
referenced by the policy), his or her name and
password are validated by the RADIUS system.
•
The user is granted access to the external network.
•
The appliance now classifies packets from the user’s
computer as traffic from the “Engineering” domain
tenant.
•
Finally, after a set idle time expires, the connection is
broken, and that user will have to log in and re-
authenticate before being granted access to the external
network again.
One of the advantages of creating and applying user-
domain tenants to policies is that there is no strict relation-
ship between a tenant and the originating computer’s IP
address. The computer used by a tenant user is noted
dynamically by the appliance during the authentication
process; the user name, password, and domain are the key,
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...