Configuring Remote Access Users
In the VPN > Remote Access Users page you can configure remote access permissions for users and groups.
Users and user groups can be configured in other pages as well (Users & Objects > Users). This page is dedicated to those with remote access permissions. You can add through it:
-
New local users
-
New users groups
-
Active Directory group
-
Active Directory permissions
-
RADIUS group
You can also set SSL VPN bookmarks by user, user group, RADIUS users and Active Directory group.
If no authentication servers are defined, click the Active Directory / RADIUS server link to define them.
Note that when User Awareness is turned off, there is no user identification based on Browser-Based Authentication and Active Directory Queries.
To add a new local user with remote access permissions:
-
Click Add > New Local User.
-
In the Remote Access tab in the window that opens, enter this information:
-
User name
-
Password - Enter this again in the Confirm field.
Note - The password can be up to 100 characters.
- Comments (optional)
-
-
For temporary or guest users, click Temporary user.
Enter the expiration date and time.
-
Do not clear the Remote Access permissions checkbox.
-
In the SSL VPN Bookmarks tab, configure the SSL VPN bookmarks (see below).
-
Click Apply.
The user is added to the table on the page.
To add a new local users group with remote access permissions:
-
Click Add > New Users Group.
-
In the Remote Access tab, enter the group name.
-
Do not clear the Remote Access permissions checkbox.
-
Select initial users to add to the group by clicking the relevant checkboxes from the user list or click New to create new users.
You can see a summary of the group members above the user list. You can remove members by clicking the X next to the relevant user name.
-
In the SSL VPN Bookmarks tab, configure the SSL VPN bookmarks (see below).
-
Click Apply.
The group is added to the table on the page.
To add remote access permissions to an existing Active Directory group:
-
Click Add > Active Directory Group.
-
If no Active Directory was defined, you are prompted to configure one. For more information on configuring Active Directory see VPN > Authentication Servers.
-
When an Active Directory has been defined, you see a list of available user groups defined in the server.
-
Select one of the user groups.
-
Click Apply.
The Active Directory group is added to the table on the page.
To add remote access permissions to all users in defined in an Active Directory:
-
Click Edit Permissions or Add > Active Directory Permissions.
-
Select All users in Active Directory. With this option, it is not necessary to use the VPN > Remote Access Users page to select specific users.
Note that most Active Directories contain a large list of users and you might not want to grant them all remote access permissions to your organization. Usually you keep the Selected Active Directory user groups option.
-
Click Apply.
The Active Directory is added to the table on the page.
To add remote access permissions for users defined in the RADIUS group:
-
Click Add > RADIUS Group.
-
If no RADIUS group was defined, you are prompted to configure one.
-
Select or clear the Enable RADIUS authentication for remote access users checkbox.
-
When selected, choose which users are given remote access permissions:
-
To allow all users defined in the RADIUS server to authenticate - Select All users defined on RADIUS server
-
Specific user groups defined in the RADIUS server - Select For specific RADIUS groups only and enter in the text field the names of the user groups separated by commas
-
To allow administrators with read-only permissions to authenticate - Select Read-only Administrators
-
-
Click Apply.
The RADIUS server or specific users from the RADIUS server are added to the table on the page.
To configure SSL VPN bookmarks:
-
Click Add > New Local User/Users Group/Active Directory Group > SSL VPN Bookmarks tab.
A new window opens.
-
Enter new bookmarks or select existing bookmarks.
Note - If you select Global bookmark, this bookmark is always shown.
-
Click Apply.
To edit a user or group:
-
Select the user or group from the list.
-
Click Edit.
-
Make the relevant changes and click Apply.
To delete a user or group:
-
Select the user or group from the list.
-
Click Delete.
-
Click OK in the confirmation message.
The user or group is deleted.