Page 151 / 249 Scroll up to view Page 146 - 150
Virtual Private Networking
146
Configuring user accounts for VPN server
After setting up the VPN server, select
Continue
and to show the
PPTP VPN Server
Accounts
screen as shown in the following figure:
Figure 9-4
If you selected
None
as the
Authentication Scheme
, setup is now complete.
Skip
ahead to
Configuring the remote VPN client
.
Otherwise, before remote users can establish VPN tunnels to the CyberGuard SG
appliance PPTP server, user accounts must be added.
Note
PPTP Accounts are distinct from those added through Users in the System menu and
those added through L2TP Server and Dialin Access. It is possible, however, to create
any of these three accounts sharing the one username and password combination.
This
may be easier than remembering two or three separate usernames and/or passwords.
For security reasons, it is recommended that you do not use your ISP username and
password for these accounts.
Page 152 / 249
Virtual Private Networking
147
The field options in the
Add New Account
are detailed in the following table.
Field
Description
Username
Username for VPN authentication only.
The name selected is case-
sensitive (e.g.
Jimsmith
is different to
jimsmith
).
Username can be
the same as, or different to, the name set for dialin access.
Windows Domain
Most Windows clients expect you to specify a domain name in
upper case. This field is optional.
Password
Enter the password for the remote VPN user.
Confirm
Re-enter the password to confirm.
As new VPN user accounts are added, they are displayed on the updated
Account List
.
To modify the password of an existing account,
Select
the account in the
Account List
and then enter
New Password
and
Confirm
in the
Delete or Change Password for the
Selected Account
field.
To delete an existing account,
Select
the account in the
Account List
and then check
Delete
in the
Delete or Change Password for the Selected Account
field.
If a requested change to a user account is successful, the
PPTP VPN Setup
screen is
shown with the change noted.
An error is displayed if the change request is
unsuccessful.
Page 153 / 249
Virtual Private Networking
148
Configuring the remote VPN client
The remote VPN clients can now be configured to securely access the local network.
You need to enter the a PPTP Account username and password that you added in the
previous section, and the IP address of the CyberGuard SG PPTP VPN server.
The CyberGuard SG PPTP VPN server IP address is displayed on the Diagnostics page.
This will generally be the same as the IP address of your main Internet connection.
Figure 9-5
Note
the current IP address of the CyberGuard SG appliance PPTP server.
This address
may change if your ISP has not allocated you a static IP address.
One solution to this is
to set up a
Dynamic DNS
service for use by your CyberGuard SG appliance (see
Dynamic DNS
in the
Network Connections
section).
Ensure the remote VPN client PC has Internet connectivity.
To create a VPN connection
across the Internet, you must set up two networking connections.
One connection is for
ISP, and the other connection is for the VPN tunnel to your office network.
Ensure that both the VPN and Dial Up Networking (DUN) software is installed on the
remote PC.
If you are using Windows 95 or an older version of Windows 98 (first
edition), install the
Microsoft DUN update
(available on the CyberGuard SG Installation
CD) and
VPN Client update.
Your CyberGuard SG appliance’s PPTP server will operate with the standard Windows
PPTP clients in all current versions of Windows.
The following sections provide details for client setup in Windows 95/98/Me and Windows
2000/XP.
More detailed instructions are available in the Windows product
documentation, and from the Microsoft website.
Page 154 / 249
Virtual Private Networking
149
Windows 95, Windows 98 and Windows Me
From the Dial-Up Networking folder, double-click
Make New Connection
.
Type
CyberGuard SG appliance
or a similar descriptive name for your new VPN connection.
From the
Select a device
drop-down menu, select the
Microsoft VPN Adapter
and click
Next
. Enter the PPTP IP address of the CyberGuard SG appliance VPN server in the
VPN Server
field.
This may change if your ISP uses dynamic IP assignment.
Click
OK
and then click
Finish
.
Figure 9-6
Right-click the new icon and select
Properties
.
Select the
Server Types
tab and check the
Log on to network
and
Enable software
compression
checkboxes.
Leave the other
Advanced Options
unchecked.
Select the
TCP/IP
network protocols from the
Allowed network protocols
list.
Warning
Ensure NetBEUI and IPX are
not
selected.
If an unsupported protocol is selected, an
error message is returned.
Page 155 / 249
Virtual Private Networking
150
Click
TCP/IP Settings
.
Confirm that the
Server Assigned IP Address
,
Server
Assigned Name Server Address
,
Use IP Header Compression
and
Use Default
Gateway on Remote Network
are all selected and click
OK
.
Figure 9-7
Your VPN client is now set up and ready to connect.
Windows 2000
Log in as
Administrator
or with Administrator privileges.
From the
Start
menu, select
Settings
and then
Network and Dial-up Connections
.
A window similar to the
following will be displayed.
Figure 9-8

Rate

4 / 5 based on 3 votes.

Popular SnapGear Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top