CHAPTER 12: Creating a Remote User VPN Policy
348
Vcontroller
Controlling a remote user’s access privileges
In addition to authenticating remote users, Firebox Vclass
appliances can also be configured to assign a temporary
internal IP address to a remote user. Typically, a remote
user can be assigned to a specific user group. Each user
group can be associated with an address group, which pro-
vides a pool of IP addresses for assignment.
After a remote user has been assigned an IP address, this
address is subject to the security policies defined within
the Policy Manager. Therefore, by controlling the network
address assignment for a group of users, a network admin-
istrator can establish different levels of access privileges for
whole groups of users.
Associating an address group to a user group allows you to
control which part of the corporate networks can be
accessed by users in a particular user group. This capabil-
ity allows network administrators to set up different user
groups for different levels of remote access.
Monitoring Remote User Activity
WatchGuard recommends that you take advantage of the
Log Manager features. You can track and record remote
access connections and system use.
Summary of Contents for Firebox V10
Page 1: ...WatchGuard Firebox Vclass User Guide Vcontroller 5 0 ...
Page 32: ...xxxii Vcontroller ...
Page 40: ...CHAPTER 1 Introduction 8 Vcontroller ...
Page 52: ...CHAPTER 2 Service and Support 20 Vcontroller ...
Page 70: ...CHAPTER 3 Getting Started 38 Vcontroller ...
Page 110: ...CHAPTER 4 Firebox Vclass Basics 78 Vcontroller ...
Page 190: ...CHAPTER 7 Using Account Manager 158 Vcontroller ...
Page 268: ...CHAPTER 9 Security Policy Examples 236 Vcontroller ...
Page 410: ...CHAPTER 14 Monitoring the Firebox Vclass 378 Vcontroller ...
Page 456: ...CHAPTER 18 Using the Diagnostics CLI Feature 424 Vcontroller ...