Thin Client Solution Installation Guide Version 2.0.0.9 Version 7 Document Version 2.0.0.9-1.0-20/02/2013 Version 7 Version 7
Important Notice Cyberoam Technologies Pvt. Ltd. has supplied this Information believing it to be accurate and reliable at the time of printing, but is presented without warranty of any kind, expressed or implied. Users must take full responsibility for their application of any products. Cyberoam Technologies Pvt. Ltd. assumes no responsibility for any errors that may appear in this document. Cyberoam Technologies Pvt. Ltd. reserves the right, without notice to make changes in product design or specifications. Information is subject to change without notice. USER S LICENSE Use of this product and document is subject to acceptance of the terms and conditions of Cyberoam End User License Agreement (EULA) and Warranty Policy for Cyberoam UTM Appliances. You will find the copy of the EULA at http://www.cyberoam.com/documents/eula.html and the Warranty Policy for Cyberoam UTM Appliances at http://kb.cyberoam.com. RESTRICTED RIGHTS Copyright 1999-2013 Cyberoam Technologies Pvt. Ltd. All rights reserved. Cyberoam, Cyberoam logo are trademark of Cyberoam Technologies Pvt. Ltd. Corporate Headquarters Cyberoam Technologies Pvt. Ltd. 901, Silicon Tower, Off. C.G. Road, Ahmedabad 380006, INDIA Phone: +91-79-66065606 Fax: +91-79-26407640 Web site: www.cyberoam.com 1/16
Technical Support You may direct all questions, comments, or requests concerning the software you purchased, your registration status, or similar issues to Customer care/service department at the following address: Corporate Office Cyberoam Technologies Pvt. Ltd. 904, Silicon Tower Off C.G. Road Ahmedabad 380015 Gujarat, India. Phone: +91-79-66065606 Fax: +91-79-26407640 Web site: www.cyberoam.com Cyberoam contact: Technical support (Corporate Office): +91-79-66065777 Email: support@cyberoam.com Web site: www.cyberoam.com Visit www.cyberoam.com for the regional and latest contact information. 2/16
Contents Technical Support... 2 Cyberoam Authentication for Thin Client (CATC)... 5 Feature Overview... 5 Configuration Steps... 5 Behavior & Limitations... 15 3/16
Typographic Conventions Material in this manual is presented in text, screen displays, or command-line notation. Item Convention Example Server Client User Username Part titles Bold and shaded font typefaces Machine where Cyberoam Software - Server component is installed Machine where Cyberoam Software - Client component is installed The end user Username uniquely identifies the user of the system Report Topic titles Shaded font typefaces Introduction Subtitles Bold & Black typefaces Notation conventions Navigation link Bold typeface Group Management Groups Create it means, to open the required page click on Group management then on Groups and finally click Create tab Name of a particular parameter / field / command button text Cross references Lowercase italic type Hyperlink in different color Enter policy name, replace policy name with the specific name of a policy Or Click Name to select where Name denotes command button text which is to be clicked refer to Customizing User database Clicking on the link will open the particular topic Notes & points to remember Bold typeface between the black borders Note Prerequisites Bold typefaces between the black borders Prerequisite Prerequisite details 4/16
Cyberoam Authentication for Thin Client (CATC) For authenticating all the users connected to Cyberoam either through Microsoft Windows Server (Microsoft TSE) or Citrix Presentation Server, a feature of Cyberoam Authentication for Thin Client (CATC) has been developed. Feature Overview Cyberoam Authentication for Thin Client (CATC) provides a solution for authenticating thin client users through Citrix Server or Microsoft Windows Server (Microsoft TSE), and also configuring per user policies. The solution consists of two deployable components. One is the CATC that is to be installed on Microsoft TSE or Citrix Server and the other component is to be configured with Cyberoam for providing the support for CATC. When any thin client user tries to logon to Citrix or Microsoft TSE, Active Directory Server (ADS) authenticates the user. Again, when the logged in users try to access the Internet, CATC will communicate with Cyberoam and provide information for identifying the users who are making the request. Once the users are identified, they will be able to access Internet based on the policies applied on them. UDP and ICMP requests can also be handled, if a firewall rule for the same is created in Cyberoam. With the creation of rules, applications like Skype can be allowed and monitored. Even if Cyberoam is used as a HTTP proxy, the feature will work properly. Thus, the feature enables user to login to Cyberoam with session oriented authentication and user based rules will be applied. Configuration Steps For authenticating users using thin client, CATC has to be installed on Microsoft TSE or Citrix Server. The current configuration is compatible with Active Directory Server only. Apart from CATC, there is another simple configuration to be done in Cyberoam. Step A. Microsoft TSE or Citrix Presentation Server Configuration: Below given are the steps of installing CATC on Microsoft TSE or Citrix Presentation Server. Prerequisite This solution is developed for Windows Server 2003, 2008 and Citrix Presentation Server only. At least 2.0 MB of free disk space is required for CATC installation to complete. 5/16
Step 1. Download CATC Installer Download CATC Installer from http://cyberoam.com/cyberoamclients.html Click Thin Client tab and download CATC Installer. Follow the onscreen instructions. Screen Cyberoam Clients Step 2. Select Language Select the language to be used during the CATC installation process. The available options for language are Chinese-Simplifies, Chinese-Traditional, English and Hindi. English the default language used during the CATC installation. Screen Select Language 6/16
Step 3. Server Restart Extract and double click the downloaded CATC Installer Exe to start the installation wizard. A warning message is displayed which suggests that once the installation is completed, the server has to be restarted. Click Yes to proceed with installation. Screen Server Restart Warning Step 4. Start Installation Setup wizard welcome screen opens. Click Next to proceed. Screen Setup Wizard 7/16
Step 5. Specify Installation Folder Click Next to install CATC at the default location. Click Browse to change the location and specify a destination folder. Once the destination is selected, click Next. Note At least 2.0 MB of free disk space is required for installation to complete. Client will not be installed, if there is no enough disk space. Screen CATC Destination Location 8/16
Step 6. Specify Start Menu folder Click Next to create the program s shortcut at the default location. Click Browse to change the location and specify a destination folder. Once the destination is selected, click Next. To avoid creating a folder in Start Menu, select Don t create a Start Menu Folder Screen Start Menu Folder 9/16
Step 7. Select Additional Tasks Enable the respective checkboxes if you want create a CATC icon on desktop or Quick launch icon. Screen Select Additional Tasks 10/16
Step 8. Install CATC Click Install to install Cyberoam Authentication for Thin Client components at mentioned locations or click Back to change the location. Screen CATC Install 11/16
Step 9. Cyberoam Settings Specify Cyberoam Settings for establishing communication between Microsoft TSE/Citrix User and Cyberoam. Specify the list of Users that are to be excluded from the list. Click Add button to add a new user, Edit button to update the details and Remove button to delete the existing user. Also, specify the Log Out Polling Time Minimum time (in seconds) before thin client user actually gets logged out from the system after pressing Log out. Screen Cyberoam Settings for CATC 12/16
Step 10. Completing the CATC Setup Once the installation is completed successfully, below provided screen is displayed. Restart the server to complete the installation. You can also re-configure the above Settings by clicking on the CATC from your desktop or start menu. Screen Completing CATC Setup Wizard 13/16
Step B. Configuration on Cyberoam Once the CATC is installed, the configuration has to be done in Cyberoam from console. You need to add the Citrix Server IP address to Cyberoam for communication with the server. Execute the following command from CLI console: Console> cyberoam auth thin-client add citrix-ip <ip address of citrix server> 14/16
Behavior & Limitations 1. This solution is developed for, Windows Server 2003, 2008 and Citrix Presentation Server. 2. Two different kinds of behavior can be observed for SSO client and CTAS. As the user authentication is carried out through Active Directory Server, number of users created in Cyberoam differs with SSO and CTAS. The details are given below: SSO There will be two simultaneous users existing in Cyberoam. One as the Cyberoam SSO client user and other as the Thin Client user. CTAS There will be three simultaneous users existing in Cyberoam. One as the Cyberoam CTAS client user, the second CTAS Terminal server user and third as the Thin Client user. 3. If simultaneous user login limit is configured, user can simultaneously logon to cyberoam for the provided number of times only. 4. Also, if the simultaneous user login limit is set to 1 and user is logged in from HTTP client/sso/ctas, user will not be able to login using thin client or visa versa. 5. Up to 64 Citrix Server configurations are supported with Cyberoam. 6. Configured Surfing Quota Policy, Access Time Policy and Data Transfer Policy will be applicable only on the next user logon. 15/16