SSL Web Proxy. Generally to access an internal web server which is behind a NAT router, you have the following two methods:



Similar documents
Web Authentication Application Note

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

Howto: How to configure static port mapping in the corporate router/firewall for Panda GateDefender Integra VPN networks

Configuration Guide. How to Configure SSL VPN Features in DSR Series. Overview

If you have questions or find errors in the guide, please, contact us under the following address:

Initial Access and Basic IPv4 Internet Configuration

Configuring Global Protect SSL VPN with a user-defined port

SSL SSL VPN

Network Configuration Settings

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

PPTP Server Access Through The

For more information refer: UTM - FAQ: What are the basics of SSLVPN setup on Gen5 UTM appliances running SonicOS Enhanced 5.2?

Connecting an Android to a FortiGate with SSL VPN

Zeroshell: VPN Host-to-Lan

Using SonicWALL NetExtender to Access FTP Servers

Chapter 4 Firewall Protection and Content Filtering

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

Firewall VPN Router. Quick Installation Guide M73-APO09-380

Protecting the Home Network (Firewall)

DDNS Management System User Manual V1.0

Multi-Homing Dual WAN Firewall Router

Chapter 1 Configuring Basic Connectivity

VPN: Using WebVPN SSL Client This document outlines the process for using the WebVPN SSL with Internet Explorer and Firefox

Change Advanced Proxy Server Configuration Settings

F-SECURE MESSAGING SECURITY GATEWAY

Best Practices: Pass-Through w/bypass (Bridge Mode)

VPN: Using the WebVPN SSL Client

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

AXIS Camera Companion Internet access

Dynamic DNS How-To Guide

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

How To Configure Apple ipad for Cyberoam L2TP

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

Using a VPN with Niagara Systems. v0.3 6, July 2013

Multi-Homing Security Gateway

Setup Corporate (Microsoft Exchange) . This tutorial will walk you through the steps of setting up your corporate account.

emerge 50P emerge 5000P

Remote extensions and remote offices

Configuring SSH Sentinel VPN client and D-Link DFL-500 Firewall

Talk-101 User Guides Mailgate Administration Guide

Startup guide for Zimonitor

Enable VPN PPTP Server Function

Chapter 9 Monitoring System Performance

SETTING UP REMOTE ACCESS ON EYEMAX PC BASED DVR.

Sophos UTM. Remote Access via PPTP Configuring Remote Client

F-Secure Messaging Security Gateway. Deployment Guide

OvisLink 8000VPN VPN Guide WL/IP-8000VPN. Version 0.6

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

Fireware Essentials Exam Study Guide

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Document No. FO1001 Issue Date: Draft: Work Group: FibreOP Technical Team October 1, 2013 Final:

VPN PPTP Application. Installation Guide

Connecting EWS using DDNS

NAT (Network Address Translation)

NAS 224 Remote Access Manual Configuration

A: The default WAN IP address is with subnet mask

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Savvius Insight Initial Configuration

PineApp Archive-Secure Quick Installation Guide:

Clientless SSL VPN Users

Accessing the Media General SSL VPN

Remote Access via VPN Configuration (May 2011)

Migration Manual (For Outlook Express 6)

D-Link DAP-1360 Repeater Mode Configuration

Virtual Private Network and Remote Access Setup

Scenario 1: One-pair VPN Trunk

University of Central Florida UCF VPN User Guide UCF Service Desk

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

SSL VPN Setup for Windows

Hosted Microsoft Exchange Client Setup & Guide Book

Firewall Defaults, Public Server Rule, and Secondary WAN IP Address

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

How To Remotely View Your Security Cameras Through An Ezwatch Pro Dvr/Camera Server On A Pc Or Ipod (For A Small Charge) On A Network (For An Extra $20) On Your Computer Or Ipo (For Free

Campus VPN. Version 1.0 September 22, 2008

aprompt User Guide Setting up a mailbox on the Apple IPhone 3G aprompt.co.uk User Guide Version 3.0 Advanced Mailbox on Apple IPhone 3G

SSL VPN Server Guide Access Manager 3.1 SP5 January 2013

Hosted Microsoft Exchange Client Setup & Guide Book

DEPLOYMENT OF I M INTOUCH (IIT) IN TYPICAL NETWORK ENVIRONMENTS. Single Computer running I m InTouch with a DSL or Cable Modem Internet Connection

Chapter 6 Virtual Private Networking Using SSL Connections

OpenVPN Setup Zeroshell By Cristian Benítez

ADTRAN 3120 / 3130 Internet Configuration Guide

What is the Barracuda SSL VPN Server Agent?

1 PC to WX64 direction connection with crossover cable or hub/switch

Stage One - Applying For an Assent Remote Access Login

Quick Installation Guide DAP Wireless N 300 Access Point & Router

GajShield UPTM Certification Module 4. GajShield Infotech Pvt Ltd

Chapter 4 Firewall Protection and Content Filtering

How To Configure A Kiwi Ip Address On A Gbk (Networking) To Be A Static Ip Address (Network) On A Ip Address From A Ipad (Netware) On An Ipad Or Ipad 2 (

IOS 8: Configure IMAP/POP/SMTP

Training module 2 Installing VMware View

Chapter 4 Security and Firewall Protection

Using a VPN with CentraLine AX Systems

Authentication Node Configuration. WatchGuard XTM

Chapter 1 Configuring Internet Connectivity

Sophos UTM. Remote Access via SSL Configuring Remote Client

IRMACS Setup. Your IRMACS is available internally by the IMAP protocol. The server settings used are:

How to convert a wireless router to be a wireless. access point

How to use EasyDDNS by HIKVISION. All rights reserved. 1

Transcription:

SSL Web Proxy Vigor2930, Vigor2950 and VigorPro 5500/5510 series router support SSL Web Proxy function to let user access lots of servers in security via Internet environment. We provide a general user application as a reference including case description and configuration of Web interface. There are two modes supported in this feature including Secured Port Redirection mode and SSL mode. Please refer to the following introduction about related application and configuration. Introduction Generally to access an internal web server which is behind a NAT router, you have the following two methods: 1. Open relevant ports (Usually TCP 80) on the router. 2. Connect a traditional VPN tunnel (PPTP, L2TP or IPSec) to the router. Drawbacks of the above methods: 1.If the web server contains private or restricted information which just allow authorized access, open port is a potential security hole for hackers to exploit for invasion or file transfer. In this case, most administrators don t select open port. 2. There are many blocking issues involving connections in relation to GRE port blocking or ESP/AH port blocking. And there are many IPSec NAT incompatibility problems. So if you are on a business trip, it happens frequently that you can t connect a VPN to your company s router caused by the router/firewall in hotel, airport, etc. Advantages of SSL Web proxy Secured Port Redirection mode: It works like Open Port but the port opened by router is random and temporary. The random port is opened when the session is established, and closed when the connection is dropped. SSL mode: It uses HTTPS to establish a secure connection. Typical port blocking is decreased. No NAT incompatibility problem. No static IPs are required, and a VPN client is unnecessary. Application Note (Secured Port Redirection mode)

Figure 1 OTRS is a working system which just permits the Support department to access. Gforge is another system which permits the Support, Sales, R&D etc. department to access. Both systems are based on web services. User A belongs to the Support department, and User B belongs to the Sales department. They are on business trips and need to access the systems from the Internet. Configurations on the Router : 1. Go to the SSL VPN >> SSL Web Proxy page, and setup two entries.

2. Enter the following: Enter a name for the OTRS system. If the web server is allowed to be accessed directly through IP address, you may input the format http://ip/directory in the URL field. Here http://172.17.1.40/login.pl If you have input IP address in the URL field, you needn t setup the Host IP Address field. In fact you will find it is grayed out. Select "Secured Port Redirection". 3. Enter the following: Enter a name for the Gforge system. If the web server is restricted to be accessed from domain name, you have to input the format http://domain_name/directory in the URL field. http://swm.gforge.com Enter the IP address of the web server in the Host IP Address field Here is

Select "Secured Port Redirection". 4. Go to SSL VPN >> User Account page and add two accounts for User A and User B.

5. Enter the following: Enable the account. Setup the username/password for User A. You needn t, but you d better disable all the VPN services in this profile. Otherwise users can also connect vpn to your router by using this account. Enable SSL Web Proxy, then enable relevant web servers (here both OTRS and Gforge) for User A.

6. Enter the following: Enable the account. Setup the username/password for User B. You needn t, but you d better disable all the VPN services in this profile. Otherwise users can also connect vpn to your router by using this account. Enable SSL Web Proxy, then enable relevant web servers (here only Gforge) for User B.

7. Go to System Maintenance >> Management page and make sure HTTPS Server is enabled. If you don t want to use the standard TCP 443 port, change the port as follows. Here we change it to 4443. Steps for User A to use web proxy : 1. Open a web browser(i.e or Firefox), and go to the following URL : https://210.243.151.187:4443 2. Internet Explorer 6 will display the below security alert stating that the security certificate is valid but is not from a known source. Please accept the certificate with

confidence by pressing the Yes button. Internet Explorer 7 will display the below security alert stating that the security certificate is valid but is not from a known source. Please select the Continue to this website (not recommended) choice.

3. A login window pops up. Input the username and password for User A. 4. If login successfully, you will see a window like the one shown below. Press SSL Web Proxy.

5. This page will list all the web sites that you are allowed to access. In this example are OTRS and Gforge for User A. But you are still not able to access them for the moment. There is a button "Activate" for each web server. Press the button to open a random port and a session for an internal server. Press the "Activate" button for the server you would like to access. 6. After pressing the "Activate" button, the button changes to "Deactivate". And OTRS and Gforge become OTRS and Gforge. Now you are able to access the OTRS system and Gforge system by clicking the links OTRS and Gforge.

The OTRS system.

The Gforge system. 7. After the access, to close the session and the port you may press the Deactivate button or simply turn off the web browser.

Steps for User B to use web proxy : The steps are identical to the ones listed above. Just notice that after login successfully, the SSL Web Proxy page will just list the Gforge system for User B. Limitation of Secure Port Redirection 1. It just supports web service. 2. The web servers must be within the same subnet of the Vigor router. And they must point their default gateways to the Vigor router. Here the Vigor router is the SSL Web Proxy. Application Note (SSL mode) OTRS is a working system which is connected directly behind Vigor2950. They are within

the same subnet. Web Mail server is another system which is also behind Vigor2950 but in a different subnet than Vigor2950. User A is on a business trip and need to access both systems from the Internet. Configurations on the Router : 1. Go to the SSL VPN >> SSL Web Proxy page, and setup two entries. 2. Enter the following: Enter a name for the OTRS system. If the web server is allowed to be accessed directly through IP address, you may input the format http://ip/directory in the URL field. Here http://172.17.1.40/login.pl If you have input IP address in the URL field, you needn t setup the Host IP Address field. In fact you will find it is grayed out. Select "SSL".

3. Enter the following: Enter a name for the Web Mail. If the web server is restricted to be accessed from domain name, you have to input the format http://domain_name/directory in the URL http://ms.mailserver.com Enter the IP address of the Web Mail in the Host IP Address field. Select "SSL". field. Here is

4. Go to SSL VPN >> User Account page and add an account for User A. 5. Enter the following: Enable the account. Setup the username/password for User A. You needn t, but you d better disable all the VPN services in this profile. Otherwise users can also connect vpn to your router by using this account. Enable SSL Web Proxy, then enable relevant web servers (here both OTRS and

WebMail) for User A. 6. Go to System Maintenance >> Management page and make sure HTTPS Server is enabled. If you don t want to use the standard TCP 443 port, change the port as follows. Here we change it to 4443.

Steps for User A to use web proxy : 1. Open a web browser(i.e or Firefox), and go to the following URL : https://218.242.130.126:4443 2. Internet Explorer 6 will display the below security alert stating that the security certificate is valid but is not from a known source. Please accept the certificate with confidence by pressing the Yes button.

Internet Explorer 7 will display the below security alert stating that the security certificate is valid but is not from a known source. Please select the Continue to this website (not recommended) choice.

3. A login window pops up. Input the username and password for User A. 4. If login successfully, you will see a window like the one shown below. Press SSL Web Proxy.

5. This page will list all the web sites that you are allowed to access. In this example are OTRS and WebMail for User A. Now you are able to access them by clicking the links.

The OTRS system.

The WebMail

Secured Port Redirection vs SSL 1. They both just support web service. 2. Secured Port Redirection mode only work if the web servers are within the same subnet of the SSL Web Proxy. SSL mode doesn t have this limitation. 3. If the web server contains ActiveX controls, you d better choose Secured Port Redirection mode.