Chapter 30 System
USG20(W)-VPN Series User’s Guide
558
Authenticate Client
Certificates
Select
Authenticate Client Certificates
(optional) to require the SSL client to
authenticate itself to the USG by sending the USG a certificate. To do that the SSL
client must have a CA-signed certificate from a CA that has been imported as a
trusted CA on the USG (see
on importing certificates
for details).
Server Certificate
Select a certificate the HTTPS server (the USG) uses to authenticate itself to the
HTTPS client. You must have certificates already configured in the
My Certificates
screen.
Redirect HTTP to
HTTPS
To allow only secure Web Configurator access, select this to redirect all HTTP
connection requests to the HTTPS server.
Admin/User Service
Control
Admin Service Control
specifies from which zones an administrator can use HTTPS
to manage the USG (using the Web Configurator). You can also specify the IP
addresses from which the administrators can manage the USG.
User Service Control
specifies from which zones a user can use HTTPS to log into
the USG (to log into SSL VPN for example). You can also specify the IP addresses
from which the users can access the USG.
Add
Click this to create a new entry. Select an entry and click
Add
to create a new entry
after the selected entry.
Edit
Double-click an entry or select it and click
Edit
to be able to modify the entry’s
settings.
Remove
To remove an entry, select it and click
Remove
. The USG confirms you want to
remove it before doing so. Note that subsequent entries move up by one when you
take this action.
Move
To change an entry’s position in the numbered list, select the method and click
Move
to display a field to type a number for where you want to put it and press [ENTER] to
move the rule to the number that you typed.
#
This is the index number of the service control rule.
The entry with a hyphen (-) instead of a number is the USG’s (non-configurable)
default policy. The USG applies this to traffic that does not match any other
configured rule. It is not an editable rule. To apply other behavior, configure a rule
that traffic will match so the USG will not have to use the default policy.
Zone
This is the zone on the USG the user is allowed or denied to access.
Address
This is the object name of the IP address(es) with which the computer is allowed or
denied to access.
Action
This displays whether the computer with the IP address specified above can access
the USG zone(s) configured in the
Zone
field (
Accept
) or not (
Deny
).
HTTP
Enable
Select the check box to allow or disallow the computer with the IP address that
matches the IP address(es) in the
Service Control
table to access the USG Web
Configurator using HTTP connections.
Server Port
You may change the server port number for a service if needed, however you must
use the same port number in order to use that service to access the USG.
Admin/User Service
Control
Admin Service Control
specifies from which zones an administrator can use HTTP to
manage the USG (using the Web Configurator). You can also specify the IP addresses
from which the administrators can manage the USG.
User Service Control
specifies from which zones a user can use HTTP to log into the
USG (to log into SSL VPN for example). You can also specify the IP addresses from
which the users can access the USG.
Add
Click this to create a new entry. Select an entry and click
Add
to create a new entry
after the selected entry.
Table 241
Configuration > System > WWW > Service Control (continued)
LABEL
DESCRIPTION
Summary of Contents for ZyWall USG20-VPN
Page 17: ...17 PART I User s Guide ...
Page 18: ...18 ...
Page 99: ...99 PART II Technical Reference ...
Page 100: ...100 ...