How to configure Enterprise Cloud



Similar documents
Device LinkUP + Desktop LP Guide RDP

IBackup Drive User Guide

Name Services (DNS): This is Quick rule will enable the Domain Name Services on the firewall.

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

PineApp Surf-SeCure Quick

ShadowControl ShadowStream

NEFSIS DEDICATED SERVER

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

Configuring the WT-4 for ftp (Infrastructure Mode)

Configuring the WT-4 for ftp (Ad-hoc Mode)

WhatsUp Gold v16.3 Installation and Configuration Guide

Administrator's Guide

Configuration Guide. BES12 Cloud

SSL SSL VPN

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

Kerio VPN Client. User Guide. Kerio Technologies

Deploying F5 with Microsoft Active Directory Federation Services

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

VPN: Using WebVPN SSL Client This document outlines the process for using the WebVPN SSL with Internet Explorer and Firefox

Flexible Identity. LDAP Synchronization Agent guide. Bronze. version 1.2

ecopy ShareScan v4.3 Pre-Installation Checklist

CA VPN Client. User Guide for Windows

Configuring the WT-4 for ftp (Ad-hoc Mode)

QUANTIFY INSTALLATION GUIDE

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

Millbeck Communications. Secure Remote Access Service. Internet VPN Access to N3. VPN Client Set Up Guide Version 6.0

FAQ. How does the new Big Bend Backup (powered by Keepit) work?

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

PC Monitor Enterprise Server. Setup Guide

Server Installation Manual 4.4.1

RBackup Server Installation and Setup Instructions and Worksheet. Read and comply with Installation Prerequisites (In this document)

VPN: Using the WebVPN SSL Client

How To Configure SSL VPN in Cyberoam

CTERA Agent for Windows

G-Lock EasyMail7. Admin Guide. Client-Server Marketing Solution for Windows. Copyright G-Lock Software. All Rights Reserved.

nexvortex Setup Template

Immotec Systems, Inc. SQL Server 2005 Installation Document

AVG Business SSO Connecting to Active Directory

NETASQ SSO Agent Installation and deployment

VMware Identity Manager Connector Installation and Configuration

CTERA Agent for Mac OS-X

Configuration Guide BES12. Version 12.1

Configuration Guide BES12. Version 12.2

BlackBerry Enterprise Service 10. Version: Configuration Guide

User Guide. CTERA Agent. August 2011 Version 3.0

IIS, FTP Server and Windows

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

Clearswift Information Governance

Managing Qualys Scanners

Exchange 2013 mailbox setup guide

Konica Minolta s Optimised Print Services (OPS)

White Paper. Installation and Configuration of Fabasoft Folio IMAP Service. Fabasoft Folio 2015 Update Rollup 3

Configuring Global Protect SSL VPN with a user-defined port

TECHNICAL NOTE Stormshield Network Firewall AUTOMATIC BACKUPS. Document version: 1.0 Reference: snentno_autobackup

VoIP CONFIGURATION GUIDE FOR MULTI-LOCATION NETWORKS

Chapter 9 Monitoring System Performance

Copyright 2012 Trend Micro Incorporated. All rights reserved.

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Sonian Getting Started Guide October 2008

Configuring Sponsor Authentication

1. Navigate to Control Panel and click on User Accounts and Family Safety. 2. Click on User Accounts

Accessing TP SSL VPN

Pearl Echo Installation Checklist

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

Barracuda IM Firewall Administrator s Guide

Configuring the WT-4 for Upload to a Computer (Ad-hoc Mode)

Configuring the WT-4 for Upload to a Computer (Infrastructure Mode)

Installing and Configuring vcloud Connector

Working Folder Linkage Setup Guide

State Health Repository Tool (SHRT) Testing Instructions

NSi Mobile Installation Guide. Version 6.2

Load Balancing. Outlook Web Access. Web Mail Using Equalizer

Repeater. BrowserStack Local. browserstack.com 1. BrowserStack Local makes a REST call using the user s access key to browserstack.

V Series Rapid Deployment Version 7.5

Setting Up Your FTP Server

How To Industrial Networking

Configuration Guide BES12. Version 12.3

Investment Management System. Connectivity Guide. IMS Connectivity Guide Page 1 of 11

freesshd SFTP Server on Windows

Configuring the WT-4 for Upload to a Computer (Ad-hoc Mode)

Application Note. SIP Domain Management

CTERA Agent for Windows

DSL-G604T Install Guides

Password Reset PRO INSTALLATION GUIDE

F-SECURE MESSAGING SECURITY GATEWAY

Remote Desktop Gateway. Accessing a Campus Managed Device (Windows Only) from home.

How To - Implement Clientless Single Sign On Authentication in Single Active Directory Domain Controller Environment

Introduction to Mobile Access Gateway Installation

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

The FlexiSchools Online Order Management System Installation Guide

Configuring Security Features of Session Recording

Proof of Concept Guide

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

Administration Guide. BlackBerry Enterprise Service 12. Version 12.0

3CX IP PBX with Twilio Elastic SIP Trunking Interconnection Guide

The FlexiSchools Online Order Management System Installation Guide

SSL VPN Setup for Windows

MobileStatus Server Installation and Configuration Guide

Configuration Guide for connecting the Eircom Advantage 4800/1500/1200 PBXs to the Eircom SIP Voice platform.

WHITE PAPER Citrix Secure Gateway Startup Guide

Transcription:

How to configure Enterprise Cloud Note: Before configuring Enterprise Cloud on GajShield, make sure you have Cloud license. Important: Below configuration can be used in all type of browsing mode. When Transparent Mode or Proxy with No User Authentication is enabled, you will see IP address instead of username in the cloud users list. To check current browsing mode,go to Browsing Setup Browsing Options. 1. Go toorganization Information and fill in the details to create CA Certificate. Note: If you find this certificate created beforehand, it is the same certificate created under Browsing Setup SSL Certificate used for scanning https browsing traffic. Certificate Name: A unique name to identify the CA Certificate. Valid upto: Date till which the CA Certificate is valid, after which the certificate expires. Key Length: The encryption key size, more the key length, greater the security level & more processing power required. (Mandatory: Certificate should have key length value set to 1024) Password: The password/passphrase for the CA Certificate. LocalID: The Local Identifier for the Certificate helps the firewall to identify the CA Certificate. o FQDN: The Fully Qualified Domain Name (FQDN), FQDN must be in ASCII format. For example, myhost.test.com. o X.509 DN: An X.509 certificate binds a name to a public key value. The role of the certificate is to associate a public key with the identity contained in the X.509 certificate.

o IP Address: IP address the certificate is associated with. It can be any IP address. For example 125.11.12.13 o Email: Email address the certificate is associated with. For example support@gajshield.com Country Name: Select the country where the firewall is installed. State / Locality Name: State and Locality are full names, i.e. 'California', 'Los Angeles'. Organization Name: Full Legal Company or Personal Name, as legally registered. Organizational Unit Name: In whichever branch of your company the firewall is getting installed. For example Accounting, IT etc. Common Name: Common name is a mandatory bit of uniquely identifying data, such as FQDN or Personal Name. Email Address:Insert support email address in case of issues. Important:If your current certificate expires and you need to create a new certificate, under Browsing Setup SSL Certificate after creating the certificate, go to Enterprise Cloud Organization Information &click on, without doing any changes in the configuration click on save. After recreating the certificate you will need to delete the old cloud exe under Configuration Users and create new cloud exe. 2. Select Cloud configuration as required, under Cloud Service Information. Primary IP Information: Firstpriority will be given to this IP bycloud client. Failover IPs (Optional): Select multiple IP s of different ISPfor failover.second priority will be given to failover IP s, when primary IP is not reachable. Service: Create / select port for the cloud client to link with GajShield, use port number greater than 1024 TCP / UDP. (Note: UDP ports / services will not work when selecting cloud failover option)

Subnet for Cloud Client: Cloud Clients will use IP address from this Subnet once the clients connect to GajShield Local IP Address: Cloud Clients would connect to the LAN network through this IP. DNS: Public or Private IP which can be used by Cloud Clients to resolve dns to browse Internet / intranet. Encryption: Data is encrypted between the Cloud client and GajShield firewall, using (Blowfish, AES & Triple-DES). Select any one from the drop down list. Compression:Traffic travelling between the cloud client and GajShield firewall is compressed, when this option is kept ON. 3. Final Cloud configuration will look like the below image. To edit the existing Cloudconfiguration click on, it will allow you to change the Cloud setup. Download plan exe without password & user certificate, by clicking on. Note: After editing cloud settings, you will have to recreate the cloud exe under Configure Users tab, Restart Cloud Service and install the same exe on the client PC.

4. Go to Configure Users tab and click on. Move users or groupby simply selecting them and clicking on, from Available Users or Available Groups tab to Selected Users & Users Group List. To remove user or groups from Selected Users & Users Group List, select the users or group and click on. Valid Upto: Set expire date by clicking on for the cloud client, after the said date the cloud client will not be functional. Click on Submit buttonif the entered data is correct or click on Reset to remove the values inserted. Note: To add new users or group in clouds Available Users or Available Groups list, add them from Browsing Users Setting.

5. After adding the user to cloud services, sign the exe by clicking on Click here to sign certificates. Insert same password in both the boxes and click on submit. Note: This password can be used to disconnect or uninstall the cloud client. Important: Restart Cloud Service or Configure Users tab., if you make any changes in Organization Information tab 6. Now you can download the cloud client exe by clicking on. If you want to download only the user certificate click on save the zip folder containing 3 files. For example (ca.crt, guest-client.crt, guest-client.key) Important:Install cloud client on normal user login, & use "Run as Administrator" to installcloud client. 7. To change password of the cloud client on users PC, where the cloud client is installed. Right click on cloud icon shown onthe right side of your taskbar. Select Change Password, a pop-up will open insert old password and the new password.

8. If you have forgotten the password of the cloud client exe, you will have to re-create the user exe (repeat step 4 & 5) and download the new user certificate from the firewall (see step 6) and not the cloud client exe. Import the 3 files downloaded from the firewall in the respective boxes as shown below. Certificate downloaded from the firewall for example is guest-client.zip, contains 3 files as show below 1. ca.crt 2. guest-client.crt 3. guest-client.key Note: Import the above three files in their respective sections. Certificate File: Import guest-client.crt Key File: Import guest-client.key CA File: Import ca.crt 9. After configuring enterprise cloud, you will need to add firewall policy to allow mobile users to connect to the firewall. Go to FirewallPoliciesRules and add policies according to your organizations requirements. Show below is an example of firewall policy for cloud client. For further assistance please Contact GajShield Support on +91 22 66607450 Email: support@gajshield.com