Page 306 / 428 Scroll up to view Page 301 - 305
Overview
292
Check Point ZoneAlarm User Guide
ZoneAlarm allows a single VPN user to connect. If you need to allow VPN remote access
to multiple users, consider purchasing a Check Point Safe@Office gateway.
Note:
A locally managed Remote Access VPN Server must have a static IP address.
If you need a Remote Access VPN Server with a dynamic IP address, you must use
SofaWare Security Management Portal (SMP) management.
Note:
SecureClient/SecuRemote supports split tunneling, which means that VPN
Clients can connect directly to the Internet, while traffic to and from VPN sites
passes through the VPN Server.
Note:
This chapter explains how to define a VPN locally. However, if your router is
centrally managed by a Service Center, then the Service Center can automatically
deploy VPN configuration for your router.
Figure 8: Remote Access VPN
Page 307 / 428
Configuring a Remote Access VPN
Chapter 14: Secure Remote Access
293
Configuring a Remote Access VPN
To create a Remote Access VPN with one user
1.
On the ZoneAlarm router, enable the SecuRemote Remote Access VPN
Server.
See
Configuring the SecuRemote Remote Access VPN Server
on page 294.
2.
Set up remote VPN access for users.
See
Setting Up Remote VPN Access for Users
on page 318.
3.
On the remote user's computer, do
one
of the following:
Install SecureClient/SecuRemote VPN Client software (provided for free with
your ZoneAlarm)
For information on installing SecureClient/SecuRemote software, see
Installing
SecuRemote
on page 296.
Install a Check Point security appliance with a built-in SecuRemote VPN
Client (for example, Check Point Safe@Office) at the user's premises.
4.
On the remote user's VPN Client, add the ZoneAlarm Remote Access VPN
Server as a Remote Access VPN site.
For information on configuring SecureClient/SecuRemote software, see the User
Help. To access SecureClient/SecuRemote User Help, right-click on the VPN Client
icon in the taskbar, select
Settings
, and then click
Help
.
For information on configuring a Check Point security appliance with a built-in
SecuRemote VPN Client, refer to the appliance's user guide.
Page 308 / 428
Configuring the SecuRemote Remote Access VPN Server
294
Check Point ZoneAlarm User Guide
Configuring the SecuRemote Remote Access VPN
Server
To configure the SecuRemote Remote Access VPN Server
1.
Click
VPN
in the main menu, and click the
VPN Server
tab.
The
VPN Server
page appears.
2.
Select the
Allow SecuRemote users to connect from the Internet
check box.
Page 309 / 428
Configuring the SecuRemote Remote Access VPN Server
Chapter 14: Secure Remote Access
295
New check boxes appear.
3.
To allow authenticated users connecting from the Internet to bypass NAT
when connecting to your internal network, select the
Bypass NAT
check box.
4.
To allow authenticated users connecting from the Internet to bypass the default
firewall policy and access your internal network without restriction, select the
Bypass default firewall policy
check box.
User-defined rules will still apply to the authenticated users.
5.
Click
Apply
.
The SecuRemote Remote Access VPN Server is enabled for the specified connection
types.
Page 310 / 428
Installing SecuRemote
296
Check Point ZoneAlarm User Guide
Installing SecuRemote
If you configured the ZoneAlarm SecuRemote VPN Server, then authorized remote access
users can connect to your network using SecureClient/SecuRemote VPN Client software.
Users can download the necessary software from http://www.checkpoint.com.
Alternatively, authorized ZoneAlarm users can use the following procedure to download
and install SecureClient/SecuRemote software.
To install SecureClient/SecuRemote
1.
Connect to the ZoneAlarm Portal using HTTPS.
See
Accessing the ZoneAlarm Portal Remotely Using HTTPS
on page 47.
2.
Click
VPN
in the main menu, and click the
VPN Server
tab.
The
VPN Server
page appears.
3.
Click the
Download
link.
The
VPN-1 SecuRemote for ZoneAlarm
page opens in a new window.
4.
Follow the online instructions to complete installation.
SecureClient/SecuRemote is installed.
For information on using SecureClient/SecuRemote, see the User Help. To access
SecureClient/SecuRemote User Help, right-click on the VPN Client icon in the
taskbar, select
Settings
, and then click
Help
.

Rate

3.5 / 5 based on 2 votes.

Popular ZoneAlarm Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top