Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /home/newdedyk/domains/bkmanuals.com/public_html/includes/pages/manual_inc.php on line 26
WatchGuard Technologies V10.0 manuale d’uso - BKManuals

WatchGuard Technologies V10.0 manuale d’uso

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38

Vai alla pagina of

Un buon manuale d’uso

Le regole impongono al rivenditore l'obbligo di fornire all'acquirente, insieme alle merci, il manuale d’uso WatchGuard Technologies V10.0. La mancanza del manuale d’uso o le informazioni errate fornite al consumatore sono la base di una denuncia in caso di inosservanza del dispositivo con il contratto. Secondo la legge, l’inclusione del manuale d’uso in una forma diversa da quella cartacea è permessa, che viene spesso utilizzato recentemente, includendo una forma grafica o elettronica WatchGuard Technologies V10.0 o video didattici per gli utenti. La condizione è il suo carattere leggibile e comprensibile.

Che cosa è il manuale d’uso?

La parola deriva dal latino "instructio", cioè organizzare. Così, il manuale d’uso WatchGuard Technologies V10.0 descrive le fasi del procedimento. Lo scopo del manuale d’uso è istruire, facilitare lo avviamento, l'uso di attrezzature o l’esecuzione di determinate azioni. Il manuale è una raccolta di informazioni sull'oggetto/servizio, un suggerimento.

Purtroppo, pochi utenti prendono il tempo di leggere il manuale d’uso, e un buono manuale non solo permette di conoscere una serie di funzionalità aggiuntive del dispositivo acquistato, ma anche evitare la maggioranza dei guasti.

Quindi cosa dovrebbe contenere il manuale perfetto?

Innanzitutto, il manuale d’uso WatchGuard Technologies V10.0 dovrebbe contenere:
- informazioni sui dati tecnici del dispositivo WatchGuard Technologies V10.0
- nome del fabbricante e anno di fabbricazione WatchGuard Technologies V10.0
- istruzioni per l'uso, la regolazione e la manutenzione delle attrezzature WatchGuard Technologies V10.0
- segnaletica di sicurezza e certificati che confermano la conformità con le norme pertinenti

Perché non leggiamo i manuali d’uso?

Generalmente questo è dovuto alla mancanza di tempo e certezza per quanto riguarda la funzionalità specifica delle attrezzature acquistate. Purtroppo, la connessione e l’avvio WatchGuard Technologies V10.0 non sono sufficienti. Questo manuale contiene una serie di linee guida per funzionalità specifiche, la sicurezza, metodi di manutenzione (anche i mezzi che dovrebbero essere usati), eventuali difetti WatchGuard Technologies V10.0 e modi per risolvere i problemi più comuni durante l'uso. Infine, il manuale contiene le coordinate del servizio WatchGuard Technologies in assenza dell'efficacia delle soluzioni proposte. Attualmente, i manuali d’uso sotto forma di animazioni interessanti e video didattici che sono migliori che la brochure suscitano un interesse considerevole. Questo tipo di manuale permette all'utente di visualizzare tutto il video didattico senza saltare le specifiche e complicate descrizioni tecniche WatchGuard Technologies V10.0, come nel caso della versione cartacea.

Perché leggere il manuale d’uso?

Prima di tutto, contiene la risposta sulla struttura, le possibilità del dispositivo WatchGuard Technologies V10.0, l'uso di vari accessori ed una serie di informazioni per sfruttare totalmente tutte le caratteristiche e servizi.

Dopo l'acquisto di successo di attrezzature/dispositivo, prendere un momento per familiarizzare con tutte le parti del manuale d'uso WatchGuard Technologies V10.0. Attualmente, sono preparati con cura e tradotti per essere comprensibili non solo per gli utenti, ma per svolgere la loro funzione di base di informazioni e di aiuto.

Sommario del manuale d’uso

  • Pagina 1

    W atchGuard®Mobile VPN with IPSec Administrator Guide W atchGuard Mobile VPN v10.0 R evised: November 28, 2007[...]

  • Pagina 2

    ii Mobile User VPN ADDRESS: 505 Fifth Avenue South Suite 500 Seattle, W A 98104 SUPPORT : www .w atchguard.com/suppor t U.S. and Canada +877.232.3531 All Other Countries +1.206.521.3575 SALES: U.S. and Canada +1.800.734.9905 All Other Countries +1.206.613.0895 ABOUT WA TCHGUARD WatchGuard is a leading provider of networ k security solutions for sma[...]

  • Pagina 3

    Administrator Guide 1 1 Configure the Firebox X Edge to use Mobile VPN with IPSec The W atchGuard® Mobi le VPN with IPSec clien t is a software applica tion that is ins talled on a r emote computer . The client makes a secur e connection from the remote c omputer to your pr otected network through an unsecured network. The Mobile VPN client uses I[...]

  • Pagina 4

    Enabling Mobil e VPN for a Fir ebox User Account 2 Mobile User VPN The F irebox X Edge creates a .wgx file for a user when a Fir ebox user ’ s account i s configured f or Mobile VPN, as described in this chapter . If you want to lock the profiles for mobile users by making them read- only , see “Configuring Global Mobile VPN Client Settings” [...]

  • Pagina 5

    Administrator Guide 3 Configur ing Global Mobi le VPN Client Settings 10 Set MUVPN key exp iration in kilobytes and/or ho urs. The d efault values are 81 92 KB and 24 hours. T o remov e a size and/or time ex piration, set the v alue to zer o (0). 11 Make su re the VPN Client T ype drop- down list is set to Mobile User . This is true whether you use[...]

  • Pagina 6

    Distributing the Software and Profiles 4 Mobile User VPN 1 Y ou can choose to make the .wgx file r ead- only so that the user cannot change the secu rity polic y file. T o do this, select the Make the MUVPN client security polic y r ead- only check box. 2 Mobile VPN clients use shared Windows Internet Naming Service ( WINS) and Domain Name Syst em [...]

  • Pagina 7

    Administrator Guide 5 Distributing the Softwar e and Profiles • The end-user p rofile This file contains the user name, shared key , and settings that enable a remote computer t o connect securely over the Internet to a protected, private computer network . F or information on how to get the profile fr om the Edge, see “ Get the user’ s .wgx [...]

  • Pagina 8

    Distributing the Software and Profiles 6 Mobile User VPN[...]

  • Pagina 9

    Administrator Guide 7 2 Using Fireware Policy Manager to Configure Mobile VPN with IPSec The W atchGuard® Mobi le VPN with IPSec clien t is a software applica tion that is ins talled on a r emote computer . The client makes a secur e connection from the remote c omputer to your pr otected network through an unsecured network. The Mobile VPN client[...]

  • Pagina 10

    About Mobile VPN Client Configuration Files 8 Mobile User VPN About Mobile VPN Client Configuration Files With Mobile VPN with IPSec, the network security administrator contr ols end-user profiles. P olicy Man- ager is used to set the name of the end user and create a clien t configura tion file , or profil e, with the file extension .wgx. The .wgx[...]

  • Pagina 11

    Administrator Guide 9 Configuring the Firebox for Mobile VPN 3 Use the instruc tions pro vided here to go through each screen of the wizard. Click Next after each step . 4 Select a user aut hentica tion server Select an authentication ser ver fr om the Authentica tion Ser v er drop- down list. Y ou can authenticat e users with the internal F irebo [...]

  • Pagina 12

    Configuring the Firebox for Mobile VPN 10 Mobile User VPN 6 Direct the flow of Internet traffic: Select an option for Internet tr affic . Y ou can allow all Internet traffic between th e Mobile VPN client and the Inte rnet to use the ISP of t he client, or you can make all Internet traffic use th e VPN tunnel. If you choose to force all Internet tr[...]

  • Pagina 13

    Administrator Guide 11 Configuring the Firebox for Mobile VPN 8 Create the virtual IP address pool: Click Add to add one IP address or an IP address r ange. Repeat this step to add more virtua l IP addr esse s . Mobile VPN users will be assigned one of these IP a dd res se s w he n t he y co nn ec t t o yo ur ne tw or k. The number of IP addresses [...]

  • Pagina 14

    Modifying an Existing Mobile VPN Profile 12 Mobile User VPN Adding Users to a Firebox Mobile VPN Group T o create an Mobile VPN tunnel with the F irebox, remote users type their user nam e and passwor d to authenticate. W atchGuard® Sy stem Mana ger software uses this information to authenticate the u ser t o the Fir ebox®. T o authenticate, user[...]

  • Pagina 15

    Administrator Guide 13 Modifying an Existing Mobile VPN Profile 3 Click Edit . The Edit MUVPN Extended Authentication Group dialog box appears. Use the following fields to edit the gr oup profile: Authentication Server Select the authentication server to use for this Mobile VPN group . T o configure y our authentication ser ver , select Setup > [...]

  • Pagina 16

    Modifying an Existing Mobile VPN Profile 14 Mobile User VPN timeouts for the Mobile VPN group are always ignored because you set timeouts in the individual F irebox user ac counts. The session and idle timeouts cannot be longer than the value in th e SA Lif e field. T o set this field, from the IPSec T unnel tab of the Edit MUVPN Extended Authentic[...]

  • Pagina 17

    Administrator Guide 15 Modifying an Existing Mobile VPN Profile Phase2 Settings Select the proposal and key expiration sett ings f or the Mobile VPN tunnel. Y ou can also enable P er fect F or war d Secrecy ( PFS) or set the Diffie-Hellman group. T o change other proposal settings, click the Proposal button, and see the procedure de scribed in “D[...]

  • Pagina 18

    Modifying an Existing Mobile VPN Profile 16 Mobile User VPN Defining advanced Phase 1 settings T o define advanced Phase 1 set tings f or an Mobile VPN user profile: 1 Fro m th e IP Sec T unnel tab of the Edit MUVPN Extended A uthentication Group dialog box, select Adva nced . The Phase1 Advanced Settings dialog box appears. 2 T o change the SA (se[...]

  • Pagina 19

    Administrator Guide 17 Configuring WINS and DNS Servers 2 Fro m th e Ty p e drop- down list, select ESP or AH as the proposal method. Only ESP is suppor ted at this time. 3 Fro m th e Authentication drop- do wn list, select SHA1 or MD5 for the authenti cation method. 4 Fro m th e Encr yption drop-down list, select the encr yption method . The optio[...]

  • Pagina 20

    Locking Down an End-User Profile 18 Mobile User VPN Locking Down an End-User Profile Y ou can use the advanced se ttings to lock down th e end-user profile so that u sers can see some set- tings but not change them, and hide other settings so that users cannot change them. W e recommend that you lock down all pr ofiles so that users cannot make cha[...]

  • Pagina 21

    Administrator Guide 19 Configuring Policies to Filter Mobile VPN T raffic Configuring Policies to Filter Mobile VPN T raffic In a default configuration, Mobile VPN with I PSec users have full access privileges through a Fir ebox®, with the Any policy . T o put limits on Mobile VPN users, you must add policies to the MUVPN tab in Po li c y Ma n ag [...]

  • Pagina 22

    Re-creating E nd-User Profiles 20 Mobile User VPN Under MUVPN Group , Po lic y Manager di splays the authen tication server , in parentheses, f or the Mobil e VPN g roup . Using the Any Policy The Any policy i s added to all Mobile VPN use r gr oups by def ault. The Any policy allows traffic on all por ts and prot ocols between the Mobile VPN user [...]

  • Pagina 23

    Administrator Guide 21 Distributing the Softwar e and Profiles Distributing the Sof tware and Profiles W atchGuard® r ecommends distrib uting end-user profiles b y encr ypted email or with some other secure method. Each client computer must hav e: • Soft ware installation pack age The packages are locat ed on the W atchGuard LiveSecurity® Ser v[...]

  • Pagina 24

    Additional Mobile VPN T opics 22 Mobile User VPN T erminating IPSec connections T o fully stop VPN connections, the F irebo x must be restarted. Removing the IPSec polic y do es not stop current connections. Global VPN settings Global VPN settings on your F irebo x apply to al l manual BOVPN tunnels, managed tunnels, and Mobile VPN tunnels. Y ou ca[...]

  • Pagina 25

    Administrator Guide 23 3 Mobile VPN Client Inst allation and Connection The W at chGuard® Mobile VPN with IPSec client is installed on an em plo yee computer , whether the employee travels or works from home. The employee uses a standard Internet connectio n and acti- vates the Mobil e VPN client. The Mobile VP N client then creates an encrypted t[...]

  • Pagina 26

    Installing the Mobile VPN with IPSec Client 24 Mobile User VPN > W indows F irewall > Change Settings > Exceptions ) for UDP port 4500. This will enable Mobile VPN keep -alive packets from the Fir ebox® to reach y our client and keep the VPN tunnel up. • W e recommend that y ou check to make sure all available ser vice packs are install[...]

  • Pagina 27

    Administrator Guide 25 Installing the Mobile VPN with IPSec Client Importing the end-user profile When the co mputer restarts, the W at chGuard Mobile VPN C onnection Monitor dialog box opens. When the soft war e star ts for the first time after you install it, you get this message: There is no profile for the VPN dial-up! Do you want to use the Co[...]

  • Pagina 28

    Connecting the Mobile VPN Client 26 Mobile User VPN If the password you use is y our password on an Active Directory or LDAP server and you choose to store it, the password becomes inv alid when it changes on the authentic ation server . 7 Click Fin ish . The computer is now r eady to use Mobile VPN with IPSec. Selecting a certificate and entering [...]

  • Pagina 29

    Administrator Guide 27 Connecting the Mobile VPN Client Star t y our connec tion to the Internet through a Dial-Up Net w ork ing connection or LAN connection. Then, use the instructions below or select your prof ile, c onnect, and disconnec t by righ t- clicking the Mobile VPN icon on your W indows toolbar . 1 F rom your Wi ndows desktop , select S[...]

  • Pagina 30

    Seeing Mobile VPN Log Messages 28 Mobile User VPN 4 Use the Connection Mode drop- down list to set the connection behavior you want for this profile. - Manual - When you select manual connection mode, the cl ient does not try to restart the VPN tunnel automatically if the VPN tunnel goes down. T o restart the VPN tunnel, you must click the Con ne c[...]

  • Pagina 31

    Administrator Guide 29 Securing Y our Computer with the Mobile VPN Firewall Securing Y our Computer with the Mobile VPN Firewall The W at chGuard® Mobile VPN with IPSec cl ient in cludes two fir ewall compone nts: Link firew all The link firewall is not enabled b y default. When the link firewall is enabled, your computer will discard any packets [...]

  • Pagina 32

    Securing Y our Computer with the Mobile VPN Firewall 30 Mobile User VPN 4 Fro m th e Stateful Inspec tion dr op- down list, select when connected or always . If y ou s ele ct when connected , the link fir ewall operat es only when the VPN tunnel is active f or this profile. If y ou s ele ct alway s , the link firewall is always active , whether the[...]

  • Pagina 33

    Administrator Guide 31 Securing Y our Computer with the Mobile VPN Firewall 3 Define friendly net works and create firewall rules as described in the subsequent sections. Defining friendly networks Use the Friendly Netw orks tab to define sp ecific known networks for which you want to generate a firewall r ule set. For ex ample, if you want to us e[...]

  • Pagina 34

    Securing Y our Computer with the Mobile VPN Firewall 32 Mobile User VPN T o create a rule, click New . Use the four tabs in the Fir ewa ll Ru le En tr y dialog box to defi ne the traffic you want to control. Each tab is described below. General tab On the Gener al tab, you define the basic proper ties of your rule . Rule Name T ype a descriptiv e n[...]

  • Pagina 35

    Administrator Guide 33 Securing Y our Computer with the Mobile VPN Firewall Loc al ta b Use the Local tab to define the local IP address and por ts that are controlled by this rule, if any . We r ec- ommend that, in any rule, you configure the Local IP Addr esses setting to enable the Any IP address radio button. If you are configur ing an incoming[...]

  • Pagina 36

    Securing Y our Computer with the Mobile VPN Firewall 34 Mobile User VPN Remote tab Use the Remote tab to define the remote IP address or addr esses and ports that are controlled by this rule, if any . For example, if your firewa ll is set to deny all traffic and you want to create a rule to allow outgoing POP3 con nections, you would add th e IP ad[...]

  • Pagina 37

    Administrator Guide 35 Securing Y our Computer with the Mobile VPN Firewall[...]

  • Pagina 38

    Securing Y our Computer with the Mobile VPN Firewall 36 Mobile User VPN[...]