
User Guide 147
Configuring the MUVPN Client
Required
The mobile user must use a virtual adapter to connect with the MUVPN client. If the virtual
adapter is not available on the MUVPN client computer, the VPN tunnel cannot connect.
The remote computer is assigned WINS and DNS addresses you entered in the Firebox Users >
Settings area of the Firebox X Edge configuration pages.
• Type the IP addresses of the DNS and WINS servers for the MUVPN clients.
For more information, see “Configuring MUVPN client settings” on page 112.
Enabling MUVPN access for a Firebox user account
1 Add a new Firebox user or edit a Firebox user, as described in “Using Local Firebox Authentication”
on page 113.
2 Click the MUVPN tab.
3 Select the Enable MUVPN for this account check box.
4 Type a shared key in the related field.
The .wgx file is encrypted with this shared key. The user enters the shared key when the .wgx file is imported. Do not
give the shared key to any user that is not authorized to use this Firebox user account.
5 Type the virtual IP address in the related field.
The virtual IP address must be an address on the Firebox X Edge trusted network that is not used. This address is
used by the remote computer to connect to the Firebox X Edge.
6 From the Authentication Algorithm drop-down list, select the type of authentication.
The options are MD5-HMAC and SHA1-HMAC.
7 From the Encryption Algorithm drop-down list, select the type of encryption.
The options are DES-CBC and 3DES-CBC.
8 Set MUVPN key expiration in kilobytes and/or hours. The default values are 8192 KB and 24 hours.
To remove a size and/or time expiration, set the value to zero (0).
9 From the VPN Client Type drop-down list, select Mobile User if the remote user is connecting
from a desktop or laptop computer instead of a handheld device such as a Pocket PC.
10 Select the All traffic uses tunnel (0.0.0.0/0 IP Subnet) check box if the remote client sends all its
traffic (including usual Web traffic) through the VPN tunnel to the Firebox X Edge. This also can let
the MUVPN client connect with other networks that the Edge connects to.
If you do not select this check box, the remote user can connect with the Firebox X Edge trusted
network only. You must enable this check box for the remote user to be able to connect to:
- Networks on the other side of a Branch Office VPN tunnel that the Edge has connected.
- Computers on the Edge’s optional network.
- Networks that are behind a static route on the trusted or optional interface. For more
information, see “Making Static Routes” on page 57.
11 Click Submit.
Comentarios a estos manuales