How to Use Certificates for Additional Security



Similar documents
Using Microsoft s CA Server with SonicWALL Devices

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Astaro User Portal: Getting Software and Certificates Astaro IPsec Client: Configuring the Client...14

ECA IIS Instructions. January 2005

SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support

etoken Enterprise For: SSL SSL with etoken

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Configuring the Watchguard Edge for RADIUS authentication

TechNote. Contents. Overview. Using a Windows Enterprise Root CA with DPI-SSL. Network Security

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

Gateway-to-Gateway VPN with Certificate

NSi Mobile Installation Guide. Version 6.2

Step-by-step installation guide for monitoring untrusted servers using Operations Manager (Part 1 of 3)

Microsoft Exchange 2010 and 2007

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

APNS Certificate generating and installation

App Orchestration 2.5

IIS 6.0SSL Certificate Deployment Guide

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Configuring Windows XP/Vista L2TP client & Zeroshell

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

isupplier PORTAL ACCESS SYSTEM REQUIREMENTS

QUANTIFY INSTALLATION GUIDE

Global VPN Client Getting Started Guide

App Orchestration 2.0

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Technical Support Set-up Procedure

Customer Tips. Xerox Network Scanning HTTP/HTTPS Configuration using Microsoft IIS. for the user. Purpose. Background

If you have questions or find errors in the guide, please, contact us under the following address:

SSL VPN Setup for Windows

V310 Support Note Version 1.0 November, 2011

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Egnyte Single Sign-On (SSO) Installation for Okta

Release Notes. Contents. Release Purpose. Pre-Installation Recommendations. Platform Compatibility. Dell SonicWALL Global VPN Client 4.

Using Internet or Windows Explorer to Upload Your Site

Massey University Wireless Network Client Configuration Mac OS X

Content Filtering Client Policy & Reporting Administrator s Guide

XCM Internet Explorer Settings

Configuring Internet Authentication Service on Microsoft Windows 2003 Server

Xerox Multifunction Devices. Verify Device Settings via the Configuration Report

Device LinkUP + Desktop LP Guide RDP

Release Notes. Pre-Installation Recommendations... 1 Platform Compatibility... 1 Known Issues... 2 Resolved Issues... 2 Troubleshooting...

MultiSite Manager. Setup Guide

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

IsItUp Quick Start Manual

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

TechNote. Configuring SonicOS for MS Windows Azure

SonicOS Enhanced 3.2 LDAP Integration with Microsoft Active Directory and Novell edirectory Support

Hallpass Instructions for Connecting to Mac with a Mac

Configuring the OfficeConnect Secure Gateway for a remote L2TP over IPSec connection

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Installation Guide. SafeNet Authentication Service

Marcum LLP MFT Guide

VPN Configuration Guide SonicWALL with SonicWALL Simple Client Provisioning

How To Industrial Networking

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

Exchange 2010 PKI Configuration Guide

Livezilla How to Install on Shared Hosting By: Jon Manning

Professional Mailbox Software Setup Guide

Exchange 2003 Mailboxes

Digital Certificate Renewal(Windows Vista and Windows 7)

Wireless Network Configuration Guide

ICONICS Using the Azure Cloud Connector

Using SonicWALL NetExtender to Access FTP Servers

SETUP AND OPERATION GUIDE CLOUD PRINT. Version 1.0. January KYOCERA Document Solutions UK

Working with Office Applications and ProjectWise

Install MS SQL Server 2012 Express Edition

Deployment Guide: Transparent Mode

5. At the Windows Component panel, select the Internet Information Services (IIS) checkbox, and then hit Next.

Smart Control Center. User Guide. 350 East Plumeria Drive San Jose, CA USA. November v1.0

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

Installation Procedure SSL Certificates in IIS 7

Cloud Services ADM. Agent Deployment Guide

Global VPN Client Getting Started Guide

Census. di Monitoring Installation User s Guide

System Administration Training Guide. S100 Installation and Site Management

Chapter 4 Management. Viewing the Activity Log

CRM Migration Manager for Microsoft Dynamics CRM. User Guide

Exchange 2013 mailbox setup guide

MultiSite Manager. Setup Guide

Configuring your client to connect to your Exchange mailbox

SFTP Server User Login Instructions. Open Internet explorer and enter the following url:

How To Restore Your Data On A Backup By Mozy (Windows) On A Pc Or Macbook Or Macintosh (Windows 2) On Your Computer Or Mac) On An Pc Or Ipad (Windows 3) On Pc Or Pc Or Micro

Global VPN Client Getting Started Guide

Chapter 8 Virtual Private Networking

ADFS Integration Guidelines

How to set up the HotSpot module with SmartConnect. Panda GateDefender 5.0

SQL Server 2008 R2 Express Edition Installation Guide

How to Install and Setup IIS Server

Integration with Active Directory

Dlink DFL 800/1600 series: Using the built-in MS L2TP/IPSEC VPN client with certificates

Advanced Administration

Smart Card Authentication. Administrator's Guide

GlobalProtect Configuration for IPsec Client on Apple ios Devices

VPNC Interoperability Profile

How to: Install an SSL certificate

Transcription:

Global VPN Client How to Use Certificates for Additional Security The usage of certificates is not a subject one should not think of lightly. There are multiple ways to implement certificates for additional security and on different places. This technote handles the part where certificates are used with a Microsoft AD in combination with the Global VPN client version 3 from sonicwall. - DHCP over VPN, the sonicwall as a DHCP server - Xauth using LDAP (which in this case is already configured for usage) - Administrator privileges on AD controller In some cases it is required to lower among others the IE security settings. It might also be there are Microsoft and or administrator specific issues, not part of the scope of support. The following subjects will be discussed: 1. Installing Certificate Services 2. Retrieve Root Certificate 3. Import the Root Certificate into a Sonicwall TZ170e 4. Add a Signing Request 5. Sign the request to a valid certificate 6. Import Signed Certificate 7. Request and Install a user Certificate on remote computer 8. Export user certificate for usage in Global Client 9. Sonicwall Group VPN policy configuration 10. Import user certificate into the Global Client

1. Installing Certificate Services First step will be to install the certificates services on your Domain controller. In this example the AD is also installed on this domain controller. For this service to work, IIS is mandatory 1. To add the service, go to the control panel and open the add and remove programs part. 2. Go to add/remove windows components - components. 3. Tick the checkbox on certificate services (in details you can see both services are activated). 4. During the installation it will disable the IIS service when active, please make sure after installation the IIS service are activated again.

2. Add Root Certificate On your domain controller open a web browser and go to http://127.0.0.1/certsrv. select Retrieve the CA certificate or certificate revocation list. In the screenshots that were used for this technote, port 90 is used for the default website so you may notice this port, located in different URL s. In a basic situation the additional port in the url is not needed as port 80 for http is default.

Next step will be to download the root CA. Press Download CA Certificate and leave it on DER encoded. When downloading the Root CA certificate, please choose the location where you want to save the certificate.

3. Import the Root Certificate into a Sonicwall TZ170e For importing this certificate into a sonicwall.. we used a TZ170 enhanced with firmware 3.1.0.11 e. The certificate is saved on the local hard drive, so it can be imported like this: Press Import.

Make sure you have selected the second choice: Import a CA certificate from a PKCS#7 (.p7b),pem (.pem) or DER (.der or.cer) encoded file. Once selected browse to the location where you have saved the Root CA.

Hit the import button.

Once imported you should see the following screen where your Root CA is listed:

4. Add a Signing Request Now that the Root CA has been imported, a local certificate for the sonicwall is needed. So please go to system certificates and press the New Signing Request button:

In the following screen the request needs to be filled out with the appropriate settings. In this example we chose a 1024 bits key which we used later on as well, press generate to complete the request.

Once the request is made, it needs to be exported for signing.

When exporting, you can choose a location where you want this to be saved. The certificate property changes in this procedure to a p10 format.

Once saved the type for the certificate signing request changes to Pending request and the certificate is ready to be validated by the CA.

5. Sign the request to a valid certificate The pending request will be signed like this: Go to http://127.0.0.1/certsrv and select - request a certificate, followed by - advanced request.

Choose the option in the middle.

In the screen that follows, you have 2 options to submit the request, you can either browse to the location where you saved the pending request (p 10) or you can edit that file and copy - paste the contents. In this example we choose browse.

Now you can download the signed CA certificate to a location on your hard drive. Once completed you can import the signed request into the sonicwall. This will be handled in the next section.

6. Import Signed Certificate At this point the certificate is signed and ready to be uploaded. The following section shows how to do this. Log into the sonicwall and go to system - certificates.

On the pending request press the upload button indicated by the red circle. You will then get the additional browse screen. Click the browse button and go to the location where you have saved the signed request, as illustrated below.

After upload you will see that the Certificate has been validated. On the section validated you will see yes if no is visible follow the previous steps for completion.

7. Request and Install a user Certificate on remote computer In the previous chapters we have created a Root CA and a Certificate for the sonicwall itself. Now it is time to make the user certificate. This certificate needs to be imported afterwards in the Global Client as well as the Root CA. There are several ways to provide the user certificate to the remote user s computer. The fastest and easiest way will be described in the following section. For other methods and additional information, please visit the Microsoft web page www.microsoft.com. On your domain controller go to http://127.0.0.1/certsrv

Check the administrator here. In this example we use the administrator. Also check the key for 1024 bits. We used 1024 previously in this technote. The next important thing is to mark the keys as exportable. This way, when the certificate is imported, the fields for the private key will not be grayed out.

After submitting, click yes on the pop up and install the certificate indicated on the next page.

8. Export user certificate for usage in Global Client The user certificate has been installed in the web browser of the domain controller in this example. The following steps show how the certificate can be exported from the browser to a file. This will be in pfx format and can later on be imported in the Global VPN client. Please go to your internet explorer s internet options. Go to content and certificates. You will see the certificate in the personal tab. Click on it and export to a file using the wizard:

You are almost done with the configuration of certificate usage for the global client. The next step will be the configuration of the Group VPN policy in the sonicwall

9. Sonicwall Group VPN policy configuration In this section you configure the Group VPN policy to use the certificate First go to system certificates and press the diskette icon on the local certificate. You will get the following screen. In this example we use the distinguished name. Copy the distinguished name including the slash / at the start of the string. The string you will use will be complete of course. In this technote some entries were deleted.

After copying the distinguished name string, go to VPN - group VPN and configure the policy. Change the IPsec keying mode from IKE using preshared secret into IKE using 3 rd Part Certificates. Change the Peer ID type into the distinguished name. Change the value <NULL> into the string you copied earlier.

Press OK.

10. Import user certificate into the Global Client When the remote PC has the *.pfx file and the root CA.cer file, open up the global client and go to view certificate manager and import both files accordingly. The root ca should go to Trusted root CA and the *.pfx file goes to user certificate. Once imported, open a connection with the global client. When prompted import the user certificate and use the password for this certificate. Created by Mohammed Ouadar Jasper Krenning Sonicwall EMEA Technical support