Supplement to ViPNet VPN Documentation. Quick Start

Similar documents
ViPNet VPN in Cisco Environment. Supplement to ViPNet Documentation

Remote Setup and Configuration of the Outlook Program Information Technology Group

CenterPoint Accounting for Agriculture Network (Domain) Installation Instructions

Preparing to Deploy Reflection : A Guide for System Administrators. Version 14.1

SBClient and Microsoft Windows Terminal Server (Including Citrix Server)

CallRex 4.2 Installation Guide

TaskCentre v4.5 File Transfer (FTP) Tool White Paper

Remote Desktop Tutorial. By: Virginia Ginny Morris

Deployment Overview (Installation):

HOWTO: How to configure SSL VPN tunnel gateway (office) to gateway

This guide is intended for administrators, who want to install, configure, and manage SAP Lumira, server for BI Platform

Table of Contents. About... 18

Your Outlook Mailbox can be accessed from any PC that is connected to the Internet.

TaskCentre v4.5 Send Message (SMTP) Tool White Paper

Junos Pulse Instructions for Windows and Mac OS X

Ten Steps for an Easy Install of the eg Enterprise Suite

Click Studios. Passwordstate. RSA SecurID Configuration

Exercise 5 Server Configuration, Web and FTP Instructions and preparatory questions Administration of Computer Systems, Fall 2008

Exercise 5 Server Configuration, Web and FTP Instructions and preparatory questions Administration of Computer Systems, Fall 2008

Exchanging Files Securely with Gerstco Using gpg4win Public Key Encryption

Setup Instructions Glion Online

User Guide. Sysgem SysMan Remote Control. By Sysgem AG

AvePoint High Speed Migration Supplementary Tools

Webalo Pro Appliance Setup

WatchDox for Windows User Guide

ISAM TO SQL MIGRATION IN SYSPRO

Introduction LIVE MAPS UNITY PORTAL / INSTALLATION GUIDE Savision B.V. savision.com All rights reserved.

Software Update Notification

Helpdesk Support Tickets & Knowledgebase

STIOffice Integration Installation, FAQ and Troubleshooting

Instructions for Configuring a SAFARI Montage Managed Home Access Expansion Server

Client Application Installation Guide

MaaS360 Cloud Extender

Aras Innovator Internet Explorer Client Configuration

Interaction Manager OFT 605 (Part1)

Installation Guide Marshal Reporting Console

How To Install An Orin Failver Engine On A Network With A Network Card (Orin) On A 2Gigbook (Orion) On An Ipad (Orina) Orin (Ornet) Ornet (Orn

Using Identity Finder. ITS Training Document

Telelink 6. Installation Manual

3. Change the Incoming Mail (POP3) information to the POP3 or Incoming Mail Server Name provided when your account is setup.

Blue Link Solutions Terminal Server Configuration How to Install Blue Link Solutions in a Terminal Server Environment

Uninstalling and Reinstalling on a Server Computer. Medical Director / PracSoft

Connecting to

KronoDesk Migration and Integration Guide Inflectra Corporation

Emulation Tech Note 12 Testing XDS560V2 STM Emulator s Ethernet Port on Wi-Fi

SQL 2005 Database Management Plans

Adobe Sign. Enabling Single Sign-On with SAML Reference Guide

TECHNICAL BULLETIN. Title: Remote Access Via Internet Date: 12/21/2011 Version: 1.1 Product: Hikvision DVR Action Required: Information Only

Setup O365 mailbox access on MACs

Outlook Web Access Training Light Version: Using a browser other than Internet Explorer 6.0 or later. A NWOCA Training Session

Kaltura Video Extension for SharePoint 2013 Deployment Guide for Microsoft Office 365. Version: 1.0

User Manual Brainloop Outlook Add-In. Version 3.4

McAfee Enterprise Security Manager. Data Source Configuration Guide. Infoblox NIOS. Data Source: September 2, Infoblox NIOS Page 1 of 8

PBX Remote Line Extension using Mediatrix 4104 and 1204 June 22, 2011

Microsoft has released Windows 8.1, a free upgrade to Windows 8. Follow the steps below to upgrade to Windows 8.1.

Installation Guide Marshal Reporting Console

Kaltura Video Solutions for Sharepoint 2013 Deployment Guide for Microsoft Office 365. Version: 1.0

Connector for Microsoft Dynamics Installation Guide

Configuring an Client for your Hosting Support POP/IMAP mailbox

TaskCentre v4.5 SMTP Tool White Paper

Steps to fix the product is not properly fixed issue for international clients.

Aras Innovator Internet Explorer Client Configuration

Technical Guide FAQ. Celcom Net Safe

AvePoint Privacy Impact Assessment 1

Implementing ifolder Server in the DMZ with ifolder Data inside the Firewall

NETWRIX CHANGE NOTIFIER

ViPNet Coordinator HW/VA 3.3. Administrator's Guide

USF Remote Desktop Gateway

Service Desk Self Service Overview

ViPNet Coordinator Monitor 4.3. Administrator's Guide

Regions File Transmission

Configuring and Monitoring SysLog Servers

WORKING WITH THE PROFESSIONAL ELECTRONIC PORTFOLIO TEMPLATE (EPT) TECHNICAL INSTRUCTIONS

Access to the Ashworth College Online Library service is free and provided upon enrollment. To access ProQuest:

Access EEC s Web Applications... 2 View Messages from EEC... 3 Sign In as a Returning User... 3

A Beginner s Guide to Building Virtual Web Servers

BackupAssist SQL Add-on

How to join an iconnect web conferencing session (using the Blackboard web-based program)

E-Biz Web Hosting Control Panel

990 e-postcard FAQ. Is there a charge to file form 990-N (e-postcard)? No, the e-postcard system is completely free.

User Guide Version 3.9

1) Update the AccuBuild Program to the latest version Version or later.

Lab 12A Configuring Single Sign On Service

Setup PPD IT How-to Guides June 2010

Customers FAQs for Webroot SecureAnywhere Identity Shield

MiaRec. Performance Monitoring. Revision 1.1 ( )

MPDS Configuration Sheet Windows 2000

Readme File. Purpose. What is Translation Manager 9.3.1? Hyperion Translation Manager Release Readme

ScaleIO Security Configuration Guide

AvePoint Office Connect 1.31

Password Reset for Remote Users

How To Install Fcus Service Management Software On A Pc Or Macbook

Macintosh Operating System Online Proctoring Guide

ViPNet CSP 4.0. User's Guide

Samsung Saga Software Upgrade for Microsoft Windows Vista Instructions

Release Notes. Dell SonicWALL Security firmware is supported on the following appliances: Dell SonicWALL Security 200

Software Distribution

Kurzweil 3000 Version 12 Web License

Durango Merchant Services QuickBooks SyncPay

ReCrystallize.com cviewserver Crystal Reports Scheduler Top Issues and Solutions Page 1

Transcription:

Supplement t ViPNet VPN Dcumentatin Quick Start

1991 2015 Inftecs Americas. All rights reserved. Versin: 00121-04 34 02 ENU This dcument is included in the sftware distributin kit and is subject t the same terms and cnditins as the sftware itself. N part f this publicatin may be reprduced, published, stred in an electrnic database, r transmitted, in any frm r by any means electrnic, mechanical, recrding, r therwise fr any purpse, withut the prir written cnsent f Inftecs Americas Inc. ViPNet is a registered trademark f Inftecs Americas Inc., New Yrk, USA. All brands and prduct names that are trademarks r registered trademarks are the prperty f their wners. Glbal cntacts page http://www.vipnet.cm/

Cntents Abut This Dcument... 3 Preparing fr the Setup... 3 Deplying the ViPNet Netwrk Administratr's Wrkstatin... 4 ViPNet Netwrk Manager Interface... 6 ViPNet Crdinatr Setup... 8 Installing ViPNet Client n a User's Cmputer... 8 Recmmendatins n ViPNet Crdinatr and ViPNet Client Cnfiguratin and Use... 9 Abut This Dcument This dcument is designed fr the netwrk administratrs intending t deply and cnfigure ViPNet VPN virtual private netwrks in their rganizatins. Yu can use this dcument as a quick reference t create and cnfigure a prtected netwrk, withut reading the full versin f the user's guide. Preparing fr the Setup Befre ViPNet VPN setup, think ver yur prtected netwrk structure and check netwrk cnnectin settings n the cmputer that will functin as a crdinatr. T d this: Decide n which cmputer yu are ging t deply the ViPNet netwrk administratr's wrkstatin. Yu chse either a client, r a crdinatr. Install the ViPNet Netwrk Manager prgram n the ViPNet netwrk administratr s wrkstatin. On a cmputer with installed ViPNet Netwrk Manager, deply a client (by installing ViPNet Client) r a crdinatr (by installing ViPNet Crdinatr). ViPNet Client r ViPNet Crdinatr allws yu t send keys and sftware updates frm ViPNet Netwrk Manager t ViPNet hsts, while the ViPNet Supplement t ViPNet VPN Dcumentatin. Quick Start 3

Netwrk Manager prgram is intended fr netwrk administering and cannt interact with ther hsts. Decide which prgram will be used t deply a crdinatr: ViPNet Crdinatr fr Windws, ViPNet Crdinatr HW r ViPNet Crdinatr VA. Make sure that yur ViPNet VPN license allws yu t add the chsen crdinatr type. Yu can deply ViPNet Crdinatr HW nly n the special hardware platfrm. ViPNet Crdinatr VA is an image f the ViPNet sftware that is intended fr functining in a virtual envirnment. Decide n which cmputer the crdinatr will be deplyed. Fr example, yu may install the crdinatr n a cmputer where private data are stred, and yu need t prvide prtected access t these data; r it may be any ther cmputer r server. A crdinatr must be always accessible frm all clients, in ther wrds, the cmputer with installed ViPNet Crdinatr must be always switched n and cnnected t the netwrk. Yu may establish prtected cnnectin t a crdinatr (as well as t a client) ver the RDP prtcl, r access public resurces n a crdinatr r a client. After yu have decided n which cmputer yu will deply the crdinatr, make sure that this cmputer has a static private IP address. On the DSL ruter, behind which the future crdinatr is lcated, cnfigure a prt frwarding rule fr the crdinatr's IP address. Set frwarding f UDP traffic frm prt 55777 t prt 55777. If the cmputer, n which yu are ging t install ViPNet Crdinatr, des nt have a static public IP address, cnfigure the Dynamic DNS service n the crrespnding ruter. T d this, yu shuld create an accunt n sme dynamic DNS service web site, fr example, www.dyndns.cm. Deplying the ViPNet Netwrk Administratr's Wrkstatin When yu are deplying a ViPNet netwrk based n the ViPNet VPN sftware, yu shuld deply the ViPNet netwrk administratr's wrkstatin first, by installing ViPNet Netwrk Manager, then ViPNet Client r ViPNet Crdinatr n the netwrk administratr's cmputer. Yu will use the ViPNet Netwrk Manager prgram fr netwrk administering, while the ViPNet Client r ViPNet Crdinatr prgram is required t link the administratr's wrkstatin with ther ViPNet hsts. T install the sftware n the ViPNet netwrk administratr's wrkstatin: 1 Run the ViPNet VPN setup prgram and install the ViPNet Netwrk Manager sftware n the ViPNet netwrk administratr's wrkstatin. Nte: T get yur link fr setup file dwnlad, yu shuld fill in a frm accessible by the fllwing link: http://inftecs.ru/dwnlads/cdwnlad_dem.php?i_id_file=6742 Supplement t ViPNet VPN Dcumentatin. Quick Start 4

2 Run the ViPNet VPN setup prgram again and install the ViPNet Client r ViPNet Crdinatr prgram n the ViPNet netwrk administratr's wrkstatin. On the first page f the ViPNet VPN setup prgram, select the I d have a key set (.dst file) fr this ViPNet Client (Crdinatr) check bx. Yu can create a *.dst file later in ViPNet Netwrk Manager. After the ViPNet Client r ViPNet Crdinatr sftware installatin is cmpleted, the ViPNet sftware is installed n yur cmputer. But the prgram cannt be laded because the keys are nt installed. D yu want t install the keys nw? message will be displayed. 3 Start ViPNet Netwrk Manager and register it. 4 Upn cmpleting the registratin, create the administratr passwrd. This passwrd is required nly fr the ViPNet Netwrk Manager sftware and cannt be saved. 5 The Create ViPNet Netwrk Wizard will be started. When yu start the wizard, yu have the fllwing ptins: Fllw the wizard instructins and create the basic netwrk structure. Clse the wizard and create a netwrk later. The minimum netwrk structure will be created (ne crdinatr and ne client, n which ViPNet Netwrk Manager is installed) and the main ViPNet Netwrk Manager windw will be displayed. 6 If yu cntinue wrking with the ViPNet Netwrk Creatin wizard, n the Lcatin fr the ViPNet Administratr's Wrkstatin page, chse the netwrk hst type, n which yu want t deply the ViPNet administratr's wrkstatin. 7 If necessary, n the Autmatic netwrk structure creatin page, rename crdinatrs and clients. Fllw the instructins in Preparing fr the Setup (n page 3): specify the crdinatr's lcal IP address, DNS names (dyndns), r static public IP address. 8 On the last page f the wizard, clear the Create key sets upn cmpleting ViPNet Netwrk Creatin Wizard check bx. We recmmend yu t create key sets after yu have made the required settings in ViPNet Netwrk Manager. Figure 1. The last page f the ViPNet Netwrk Creatin Wizard Upn yu have cmpleted the wizard, ViPNet Netwrk Manager will be launched. The ViPNet netwrk administratr's wrkstatin is marked with the icn r in ViPNet Netwrk Manager. 9 Decide if user passwrds shuld be saved t the registry (fr example, t make the lg prcedure quicker and easier). T d this, in the main ViPNet Netwrk Manager windw, in the navigatin pane, click the required ViPNet client, click the Keys tab, and select r clear the Allw t save passwrd check bx. 10 Upn the cnfiguratin, save key sets fr the ViPNet hsts. T d this: Supplement t ViPNet VPN Dcumentatin. Quick Start 5

On the Tls menu, select Keys, and then click Save Key Sets. Figure 2. Saving key sets In the Brwse Fr Flder windw, navigate t the flder t save the key sets t. Upn the key sets have been created, in Windws Explrer, the flder will be pened, where key sets, user passwrds f ViPNet hsts have been saved t. Key sets files have a.dst extensin and are stred in flders named after the crrespnding ViPNet hsts. ViPNet user passwrds are saved as a list in the ViPNet.txt file. Yu can view the ViPNet hst administratr's passwrd, which is valid fr all the hsts n yur ViPNet netwrk, in the My Netwrk sectin, n the Passwrds tab. 11 Open the flder created fr the ViPNet netwrk administratr's wrkstatin and duble-click the *.dst file t install the keys. 12 Open the ViPNet.txt file cntaining ViPNet user passwrds. Cpy the user passwrd fr the ViPNet netwrk administratr's wrkstatin's hst. 13 Start ViPNet Mnitr: If yu use Windws 7 r an earlier versin f the Micrsft Windws perating system, n the Start menu, chse All Prgrams > ViPNet > ViPNet Client (Crdinatr) > Mnitr If yu use the Windws 8 perating system, n the Start screen, pen the Apps list and chse ViPNet > Mnitr. ViPNet Mnitr is the ViPNet Client r ViPNet Crdinatr user interface. 14 Paste the cpied user passwrd int the Passwrd bx. If yu have allwed passwrd saving in ViPNet Netwrk Manager, yu may save the passwrd t the registry. As a result, the ViPNet Netwrk Manager and ViPNet Client r ViPNet Crdinatr sftware installatin n the ViPNet netwrk administratr's wrkstatin is cmpleted. 15 Cpy the saved key sets n a remvable drive. Yu will need them fr ViPNet Crdinatr setup (n page 8), as well as fr ViPNet Client setup when yu install the prgram n users' wrk cmputers (see Installing ViPNet Client n a User's Cmputer n page 8). ViPNet Netwrk Manager Interface The ViPNet Netwrk Manager windw is shwn in the figure belw: Supplement t ViPNet VPN Dcumentatin. Quick Start 6

Figure 3. ViPNet Netwrk Manager interface The fllwing elements are marked with numbers in the figure: 1 The menu bar. 2 The tlbar. T add r remve buttns displayed n the tlbar, n the View menu, click Custmize Tlbar. 3 The navigatin pane. Displays the tree-like structure f yur ViPNet netwrk. 4 The view pane. Displays prperties tabs fr the element currently selected in the navigatin pane. 5 My Netwrk sectin. Cntains all crdinatrs and clients f yur ViPNet netwrk. 6 Partner Netwrks sectin. This sectin is displayed nly if yu have established partner netwrk cnnectins t ther ViPNet netwrks. It cntains a list f yur partner netwrks. Supplement t ViPNet VPN Dcumentatin. Quick Start 7

ViPNet Crdinatr Setup Yu shuld install ViPNet Crdinatr n cmputers that will functin as servers in yur ViPNet netwrk. A crdinatr ensures delivery f ViPNet keys and sftware updates t clients and exchange f ViPNet hsts' status infrmatin and their current addresses. Bth a client and a crdinatr can exchange encrypted messages and files with ther ViPNet hsts. T install ViPNet Crdinatr: 1 Run the ViPNet VPN setup prgram and, in the displayed windw, click Secnd step. Deply netwrk servers (ViPNet Crdinatr installatin). 2 Fllw the instructins. Yu may leave the default settings. 3 Install the keys by duble-clicking the *.dst file yu have received frm yur ViPNet netwrk administratr. Nte: T save a *.dst file fr a ViPNet hst, in the main ViPNet Netwrk Manager windw, in the navigatin pane, select this hst. In the view pane, click the Keys tab and click Save keys. 4 Run ViPNet Crdinatr Mnitr: If yu use Windws 7 r an earlier versin f the Micrsft Windws perating system, n the Start menu, chse All Prgrams > ViPNet > ViPNet Crdinatr > Mnitr. If yu use the Windws 8 perating system, n the Start screen, pen the Apps list and chse ViPNet > Mnitr. 5 T lg n t the prgram, enter the ViPNet hst's user passwrd. Nte: The user passwrd is stred in the vipnet.txt file that is created autmatically when yu save keys t the flder. Installing ViPNet Client n a User's Cmputer Yu shuld install ViPNet Client n users' cmputers where traffic prtectin is required. T install the ViPNet Client sftware n a user's cmputer: 1 Disable the firewall integrated in applicatins such as Kaspersky Internet Security, Nrtn Internet Security and s n, if such applicatins are running n yur cmputer. Supplement t ViPNet VPN Dcumentatin. Quick Start 8

Warning: If such a prgram is running tgether with the ViPNet sftware, it may cause cnflicts because ViPNet Mnitr has its wn implemented firewall. Prgrams that d nt have an implemented firewall, fr example, Kaspersky Anti-Virus and Nrtn Anti- Virus, are cmpatible with the ViPNet sftware. 2 Run the ViPNet VPN setup prgram and, in the displayed windw, click Third step. Cnfigure ViPNet netwrk clients (ViPNet Client installatin). 3 Fllw the instructins. Yu may leave the default settings. 4 After restart, install the keys by duble-clicking the *.dst file yu have received frm yur ViPNet netwrk administratr. Nte: T save a *.dst file fr a ViPNet hst, in the main ViPNet Netwrk Manager windw, in the navigatin pane, select this hst. In the view pane, click the Keys tab and click Save keys. 5 Run ViPNet Client Mnitr: If yu use Windws 7 r an earlier versin f the Micrsft Windws perating system, n the Start menu, chse All Prgrams > ViPNet > ViPNet Client > Mnitr If yu use the Windws 8 perating system, n the Start screen, pen the Apps list and chse ViPNet > Mnitr. Nte: The user passwrd is stred in the vipnet.txt file that is created autmatically when yu save keys t the flder. Recmmendatins n ViPNet Crdinatr and ViPNet Client Cnfiguratin and Use Fr the ViPNet netwrk t functin crrectly, fllw the recmmendatins belw: The ViPNet Crdinatr must perate uninterruptedly. At ViPNet Crdinatr startup, hst user lgn shuld be required. Fr the ViPNet Crdinatr Mnitr t start autmatically even at emergency rebt, yu shuld cnfigure saving user passwrd t the registry, as well as autlgn t the perating system. Fr mre infrmatin n system autlgn cnfiguratin, see the Supplement t ViPNet VPN Dcumentatin. Quick Start 9

dcument Cmmn Scenaris f ViPNet VPN Administering. Supplement t ViPNet Dcumentatin. Never exit the ViPNet Crdinatr Mnitr and ViPNet Client Mnitr prgrams. If ViPNet Mnitr is nt running, we d nt guarantee security f yur ViPNet netwrk. T hide the main prgram windw, click Clse in the upper right crner f the windw. In ViPNet Client and ViPNet Crdinatr, an integrated persnal firewall is integrated. By default, n all ViPNet clients and crdinatrs, the netwrk filters are cnfigured that allw all public netwrk IP traffic. It means that the integrated firewall is disabled. This allws t avid netwrk access prblems if, n a ViPNet hst, anther firewall (fr example, Windws Firewall) is installed. If yu want t blck unwanted IP traffic, in ViPNet Client r ViPNet Crdinatr, cnfigure the crrespnding netwrk filters. T cntrl firewalls n the ViPNet hsts f yur netwrk centrally, we recmmend yu t use the ViPNet Plicy Manager prgram. If yu are an experienced ViPNet administratr, yu can blck all unprtected cnnectins and allw nly necessary IP traffic. In this case, disable all ther firewalls including Windws Firewall. Warning: We recmmend that yu shuld nt cnfigure allwing netwrk filters unless it is necessary. Fr mre infrmatin abut netwrk filter cnfiguring, see the dcument Cmmn Scenaris f ViPNet VPN Administering, sectin Peculiarities f the Integrated Firewall. By default, virtual IP addresses are used within a WAN, and real IP addresses are used within a LAN. Fr the IP addresses used by ViPNet hsts in yur netwrk t be displayed in the Private Netwrk sectin f the main windw: On the Service menu, click Optins. In the Optins dialg bx, in the navigatin pane, select General. In the view pane, select the Shw IP addresses in the Private Netwrk sectin check bx. Nte: T cnfigure clients, in ViPNet Mnitr sftware, lg nt the administratr mde. Supplement t ViPNet VPN Dcumentatin. Quick Start 10