Remote Access Modes

In the Remote Access page of a gateway, you can configure Visitor Mode and Hub Mode. Visitor Mode is required. Hub Mode is optional. In Hub Mode, the Security Gateway is the VPN router for clients. All connections that the client opens are passed through the Security Gateway, even connections to the Internet.

You can exclude local networks when Hub Mode is enabled.

Note - Hub mode is not supported in SecuRemote.

To enable Hub Mode:

  1. In SmartConsole, click Menu > Global Properties

  2. Open Remote Access > Endpoint Connect.

  3. Select an option in Security Settings > Route all traffic to gateway:

    • No - Clients route only VPN traffic through the Security Gateway. Traffic from the client to public sites is not routed. This is default. It prevents adverse performance on the Security Gateway due to heavier loads.

    • Yes - The clients use Hub Mode and the user cannot change this.

    • Configured on endpoint client - Clients that you pre-configure to use VPN Tunneling will use Hub Mode and the user cannot change this setting. Clients that you do not pre-configure for VPN Tunneling will use the setting that users choose.