Sophos UTM. Remote Access via IPsec Configuring Remote Client



Similar documents
Sophos UTM. Remote Access via PPTP Configuring Remote Client

Sophos UTM. Remote Access via SSL Configuring Remote Client

Sophos UTM. Remote Access via IPsec. Configuring UTM and Client

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

Astaro User Portal: Getting Software and Certificates Astaro IPsec Client: Configuring the Client...14

If you have questions or find errors in the guide, please, contact us under the following address:

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

BRIC VPN Setup Instructions

SSL SSL VPN

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

DOE VPN Client Installation and Setup Guide March 2011

8x8 Click2Pop User Guide

Contents. VPN Instructions. VPN Instructions... 1

SHC Client Remote Access User Guide for Citrix & F5 VPN Edge Client

WestermoConnect User Guide. VPNeFree Service

Global VPN Client Getting Started Guide

Last modified on for application version 4.4.4

Aventail Connect Client with Smart Tunneling

VPN Remote Access Installation and Configuration Guide Operating System: Windows (XP, Vista, 7 and 8)

How to setup a VPN on Windows XP in Safari.

Setting up a Virtual Private Network (VPN) connection Windows 8

Sophos Mobile Control Installation guide

CA VPN Client. User Guide for Windows

2X Cloud Portal v10.5

Sophos Anti-Virus standalone startup guide. For Windows and Mac OS X

Access the UTHSCSA Palo Alto Networks (PAN) VPN using Global Protect VPN client and Two Factor Authentication (2FA)

User Guide. The AMF's File Transfer Service (FTS)

VPN: Virtual Private Network Setup Instructions

Using the FDO Remote Access Portal

VPN: Using WebVPN SSL Client This document outlines the process for using the WebVPN SSL with Internet Explorer and Firefox

Installing the VPN Client for Microsoft Windows OS

Remote Access - Mac OS X

Using the FDO Remote Access Portal

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

How to Remotely Access the C&CDHB Network from a Personal Device

VPN: Using the WebVPN SSL Client

Kerio Control. User Guide. Kerio Technologies

Configuring Devices for Use with Cisco Configuration Professional (CCP) 2.5

Resource Guide INSTALL AND CONNECT TO CISCO ANYCONNECT VPN CLIENT (FOR WINDOWS COMPUTERS)

Recommended Browser Setting for MySBU Portal

Nortel VPN Client. Customer Care Center Office of Enterprise Technology (OET) for Windows Vista 64-bit Operating System

Sale Grammar School Remote Desktop Services User Instructions

VeriSign PKI Client Government Edition v 1.5. VeriSign PKI Client Government. VeriSign PKI Client VeriSign, Inc. Government.

Wavecrest Certificate

NAS 323 Using Your NAS as a VPN Server

Junos Pulse VPN Client Installation

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

MultiSite Manager. Setup Guide

SSL VPN Setup for Windows

EMR Link Server Interface Installation

mystanwell.com Installing Citrix Client Software Information and Business Systems

Global Knowledge European Remote Labs Accessing the Remote Labs portal from Windows

ez Agent Administrator s Guide

Remote Access Services Microsoft Windows - Installation Guide

Setting up Remote Desktop

TxEIS Browser Settings

Campus VPN. Version 1.0 September 22, 2008

Endpoint Security VPN for Windows 32-bit/64-bit

QUANTIFY INSTALLATION GUIDE

Sophos Mobile Control SaaS startup guide. Product version: 6

SMS for Outlook. Installation, Configuration and Usage Guide

CONNECTING TO THE DTS WIRELESS NETWORK USING WINDOWS VISTA

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

Verizon Remote Access User Guide

Using Remote Desktop with the Cisco AnyConnect VPN Client in Windows Vista

SSL VPN Support Guide

pcanywhere Advanced Configuration Guide

8x8 Virtual Office Click2Pop for eagent Setup Guide

Setting up a Virtual Private Network (VPN) connection (Windows 7)

Juniper NetScreen IPSec Dial Client. Installation Guide for Windows 2000 Windows XP Windows Vista

CTERA Agent for Mac OS-X

Mac OS VPN Set Up Guide

Remote Filtering Software

WebEx Remote Access White Paper. The CBORD Group, Inc.

Undergraduate Academic Affairs \ Student Affairs IT Services. VPN and Remote Desktop Access from a Windows 7 PC

IceWarp Notifier User Guide

Quick Setup Guide. 2 System requirements and licensing Kerio Technologies s.r.o. All rights reserved.

Print Audit 6 - SQL Server 2005 Express Edition

Virtual Owl. Guide for Windows. University Information Technology Services. Training, Outreach, Learning Technologies & Video Production

Connecting to LRDC Fileserver Remotely Using Windows Vista/7 & SRemote VPN

University of Central Florida UCF VPN User Guide UCF Service Desk

WatchGuard Mobile User VPN Guide

CONNECT-TO-CHOP USER GUIDE

FortiClient SSL VPN Client User s Guide

Connecting to LRDC Fileserver Remotely Using Windows XP & SRemote VPN

For paid computer support call

How do I Install and Configure MS Remote Desktop for the Haas Terminal Server on my Mac?

Device LinkUP + Desktop LP Guide RDP

Windows and MAC User Handbook Remote and Secure Connection Version /19/2013. User Handbook

PHD Virtual Backup for Hyper-V

ThinPoint Quick Start Guide

Sophos Mobile Control Installation guide. Product version: 3.6

VPN CLIENT USER S GUIDE

Sophos Mobile Control Installation guide. Product version: 3.5

EntraPass WebStation. Installation Manual DN

Lepide Active Directory Self Service. Installation Guide. Lepide Active Directory Self Service Tool. Lepide Software Private Limited Page 1

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

LRDC Computing Services

Transcription:

Sophos UTM Remote Access via IPsec Configuring Remote Client Product version: 9.300 Document date: Tuesday, October 14, 2014

The specifications and information in this document are subject to change without notice. Companies, names, and data used in examples herein are fictitious unless otherwise noted. This document may not be copied or distributed by any means, in whole or in part, for any reason, without the express written permission of Sophos Limited. Translations of this original manual must be marked as follows: "Translation of the original manual". 2014 Sophos Limited. All rights reserved. http://www.sophos.com Sophos UTM, Sophos UTM Manager, Astaro Security Gateway, Astaro Command Center, Sophos Gateway Manager, Sophos iview Setup and WebAdmin are trademarks of Sophos Limited. Cisco is a registered trademark of Cisco Systems Inc. ios is a trademark of Apple Inc. Linux is a trademark of Linus Torvalds. All further trademarks are the property of their respective owners. Limited Warranty No guarantee is given for the correctness of the information contained in this document. Please send any comments or corrections to nsg-docu@sophos.com.

Contents 1 Introduction 4 2 Getting Software and Certificates 5 3 Configuring the Sophos IPsec Client 7 4 Connecting to the VPN 9 5 Disconnecting from the VPN 10

1 Introduction 1 Introduction To be able to access the UTM via IPsec VPN, you need to configure your remote computer. To do so, access the UTM User Portal with a browser on the remote client. There, the necessary installation instructions, the Sophos IPsec Client software and configuration files are available for download. Then you install the software and configure the installed software. 4 UTM 9 Remote Access via IPsec

2 Getting Software and Certificates 2 Getting Software and Certificates The UTM User Portal is available to all remote access users. From this portal, you can download guides and tools for the configuration of your client. You should get the following user credentials for the User Portal from your system administrator: IP address, username, and password. Especially for the IPsec remote access based on authentication with X.509 certificate, the User Portal offers the Sophos IPsec Client software, the configuration files, and necessary keys. 1. Start your browser and open the User Portal. Start your browser and enter the management address of the User Portal as follows: https://ip address (example: https://218.93.117.220). A security note will be displayed. Accept the security note. Depending on the browser, click I Understand the Risks > Add Exception > Confirm Security Exception (Mozilla Firefox), or Proceed Anyway (Google Chrome), or Continue to this website (Microsoft Internet Explorer). 2. Log in to the User Portal. Enter your credentials: Username: Your username, which you received from the administrator. Password: Your password, which you received from the administrator. Please note that passwords are case-sensitive. Click Login. 3. On the Remote Access page, download the tools and/or configuration guide for setting up your remote access connection. This page can contain up to five sections, depending on the remote access connection types (IPsec, SSL, L2TP, PPTP, ios devices) your administrator enabled for you. At the top of most of the sections you find a help icon which opens the respective remote access guide. UTM 9 Remote Access via IPsec 5

2 Getting Software and Certificates The IPsec VPN section contains the executable client software, configuration file, and certificate (if selected) for the remote access client. In the Export password field, enter a password to secure the PKCS#12 container before downloading the certificate. Note that you will need the security password of the certificate later on. Start the download processes by clicking the respective Download button. Download all files and store them in a location of your choice. You will need all those files later on when installing and configuring the Sophos IPsec Client. 4. Close the User Portal session by clicking Log out. The rest of the configuration takes place on the Sophos IPsec Client. Note The Sophos IPsec Client runs on Windows XP, Vista, and 7. 6 UTM 9 Remote Access via IPsec

3 Configuring the Sophos IPsec Client 3 Configuring the Sophos IPsec Client First you have to start the Sophos IPsec Client installation via double-clicking the downloaded exe file and follow the necessary steps in the installation wizard. As a separate software it has its own documentation. You can instantly use the 30-day trial licence or activate the software using the purchased licence key. After installation, in order to configure the Sophos IPsec Client, proceed as follows: 1. Import the user s configuration file. The profile settings of the INI file have to be imported to the Sophos IPsec Client. In the Profile dialog box, click Add/Import. The New Profile Wizard appears. Follow the steps of the wizard to import the user s configuration file. 2. Import the PKCS#12 file. Open the Configuration > Certificates menu of Sophos IPsec Client. Click Add. Enter a Name, and as Certificate select from PKCS#12 File. Then click the button next to PKCS#12 Filename. Browse for the PKCS#12 file of the user and select it. Store the key by clicking OK and close the dialog box. 3. Assign the certificate to the user. UTM 9 Remote Access via IPsec 7

3 Configuring the Sophos IPsec Client Open the Configuration > Profiles menu on Sophos IPsec Client. In the Profile dialog box, select the imported profile, and click Edit. On the left, select the Identities entry. From the Certificate configuration drop-down list, select the previously imported certificate. Click OK. 8 UTM 9 Remote Access via IPsec

4 Connecting to the VPN 4 Connecting to the VPN In Sophos IPsec Client, click the Connection button. If the connection establishes successfully, you will see a green bar and the information Connection established, as displayed in the figure. Additionally, the Tray icon of Sophos IPsec Client switches from red to green. If you chose X.509 as authentication method, a PIN dialog will open when connecting to the VPN. In this case, enter the password you used for downloading the PKCS#12 container from the User Portal. The Sophos IPsec Client has a caching mechanism. So during normal operation (connect/disconnect) it is only necessary to enter the PIN once. It is only after a restart of your computer that you need to enter the PIN again. Alternatively, you can connect from the Sophos IPsec Client Tray icon menu. Right-click the icon, and select the Connect entry from the context menu. UTM 9 Remote Access via IPsec 9

5 Disconnecting from the VPN 5 Disconnecting from the VPN To disconnect from the VPN, click the Disconnect button. Alternatively, you can disconnect from the Sophos IPsec Client Tray icon menu. Rightclick the icon, and select the Disconnect entry from the context menu. Note The client has a timeout mechanism included. By default, Sophos IPsec Client does not close the VPN connection in case of an inactivity (default value set to 0). In order to increase this value, edit your profile in Configuration > Profile Settings, and go to the section Line Management. You can specify a higher value in Inactivity Timeout, which means that the connection will be terminated if no data is transmitted for the time specified. 10 UTM 9 Remote Access via IPsec