assumes no responsibility for the use of this information, nor any infringement of patents or other rights of
third parties which may result from its use. No license is granted by implication or otherwise under any
patent, copyright, or other intellectual property right of F5. F5 reserves the right to change specifications at
any time without notice.
Trademarks
F5, F5 Networks, the F5 logo, BIG-IP, 3-DNS, iControl, GLOBAL-SITE, SEE-IT, EDGE-FX, FireGuard,
Internet Control Architecture, IP Application Switch, Packet Velocity, iRules, SYN Check, FirePass, and
Webifyer are registered trademarks or trademarks of F5 Networks, Inc. in the U.S. and certain other
countries. All other trademarks mentioned in this document are the property of their respective owners. F5
Networks' trademarks may not be used in connection with any product or service except as permitted in
writing by F5.
Export Regulation Notice
This product may include cryptographic software. Under the Export Administration Act, the United States
government may consider it a criminal offense to export this product from the United States.
Export Warning
This is a Class A product. In a domestic environment this product may cause radio interference in which
case the user may be required to take adequate measures.
FCC Compliance
This equipment generates, uses, and may emit radio frequency energy. The equipment has been type tested
and found to comply with the limits for a Class A digital device pursuant to Part 15 of FCC rules, which
are designed to provide reasonable protection against such radio frequency interference.
Operation of this equipment in a residential area may cause interference, in which case the user at his own
expense will be required to take whatever measures may be required to correct the interference.
Any modifications to this device, unless expressly approved by the manufacturer, can void the user's
authority to operate this equipment under part 15 of the FCC rules.
Canadian Regulatory Compliance
This class A digital apparatus complies with Canadian I CES-003.
Standards Compliance
The product conforms to ANSI/UL Std 1950 and Certified to CAN/CSA Std. C22.2 No. 950.
FirePass™ Server Administrator Guidei
Page 4
ii
Page 5
Table of Contents
Page 6
Page 7
1
Introducing the FirePass Server
The FirePass remote access solution ........................................................................................1-1
The FirePass server models ........................................................................................................1-1
The FirePass server features .......................................................................................................1-2
Overview of features ............................................................................................................1-2
FirePass server features .......................................................................................................1-3
About this guide ..............................................................................................................................1-4
Accessing a slave server’s configuration while connected to a master server ........7-8
Displaying statistics for a FirePass server cluster ..........................................................7-8
Index
viii
Page 11
1
Introducing the FirePass Server
• The FirePass remote access solution
• The FirePass server models
• The FirePass server features
• About this guide
• Finding help and technical support resources
Page 12
Page 13
The FirePass remote access solution
The FirePass™ server is a network appliance providing remote users with
secure access to corporate networks, using any standard Web browser. The
FirePass server can be installed in a few hours and it requires no
modifications to corporate applications. No configuration or setup is
required at the user’s remote location. If the user’s Web browser can
connect to Web sites on the Internet, then that browser can connect to the
the FirePass server.
The FirePass server provides a web-based alternative to traditional
remote-access technologies such as modem pools, RAS servers, and
IPSec-layer Virtual Private Networks (VPNs). By leveraging the browser as
a standard “thin client,” FirePass server enables a corporation or
organization to extend secure remote access easily and cost-effectively to
anyone connected to the Internet with no special software or configuration
on the remote device. Also, no additions or changes are necessary to the
back-end resources being accessed. This approach eliminates the IPSec
VPN support burden and adds application functionality well beyond mere
connectivity.
Introducing the FirePass Server
The FirePass server provides full access to network and desktop resources,
including:
• File servers
•Email
• Intranet
• Terminal servers
• Legacy mainframe, AS/400, and Telnet applications
• Client/server applications
• All desktop PC applications
The FirePass server models
The FirePass server is available in two models:
◆
FirePass 1000:
• Supports up to 100 concurrent users
• 1U rackmount chassis
• Includes one 10/100 Ethernet port and supports an option for a second
10/100 Ethernet port
• 200 watt power supply
◆
FirePass 4000:
• Supports up to 1000 concurrent users
• 2U rackmount chassis
• Includes two 10/100 Ethernet ports
• 480 watt power supply
FirePass™ Server Administrator Guide1 - 1
Page 14
Chapter 1
The FirePass server features
Overview of features
◆
Security
FirePass server was built from the ground up to adhere to the highest
standards of best security practices.
• Encryption—FirePass server offers several strengths of encryption,
depending on the capability of the browser in use and on the optional
security settings of the FirePass implementation. FirePass server
offers encryption keys up to 1024 bits.
• Authentication—FirePass server includes an internal user database for
password authentication, and it can use existing RADIUS, LDAP, and
Windows domain servers for authentication. Administrators can
require different authentication methods for different groups. If you
want to use two-factor authentication, FirePass server supports RSA
SecurID
built-in implementation of VASCO Digipass
• Access Control—FirePass server grants access to specific
applications to individuals or to groups of users. With FirePass
server’s access controls, you can restrict individuals and groups to
particular resources. For example, partners can be have restricted
access to an extranet server only, while sales staff can connect to
email, the company Intranet, and the CRM system.
®
token-based authentication, and also offers an optional,
®
.
◆
Availability
Unlike IPSec VPNs, Web-based remote access works over all ISP
connections and works from behind other firewalls. ISPs cannot detect
and block FirePass server conversations as they might with detected
IPSec traffic. Failover and clustering options provide high availability
and high capacity. FirePass servers can be clustered to support up to
10,000 concurrent connections on a single logical URL without
performance degradation.
◆
Ease of use, deployment, maintenance, and management
FirePass server installs in a few hours. Users are presented with an
intuitive, browser-based interface and they require minimal training after
a brief introduction. FirePass server can be upgraded in the field over the
Web. Automatic release update notifications prompt the FirePass server
administrator to download new versions when they become available.
Features and capacity can also be added over the Web.
1 - 2
Page 15
FirePass server features
The following features are available on both FirePass server models.
◆
Standard Web browser support
FirePass server can be used with most standard browsers supporting
secure HTTP (also known as HTTPS). These include Internet Explorer®,
Netscape Navigator®, Opera®, and Mozilla®.
◆
WAN security
FirePass server supports common encryption technologies, including
RC4 and 3DES. It uses standard SSL encryption from the client browser
to the FirePass server.
◆
Authentication
FirePass server performs basic authentication using an internal database.
It also supports two-factor (token-based) authentication methods like
RSA SecurID® and VASCO Digipass.
FirePass server authenticates devices using signed digital certificates.
FirePass server can be integrated with LDAP directories and Windows
Domain Servers.
Introducing the FirePass Server
◆
Application access using standard Webifyers
FirePass server provides access to virtually all corporate and desktop
applications, including email, file, and Intranet access, client-server
application access, legacy host application access (mainframe, AS/400,
X-Windows, and Telnet), and Terminal Services/Citrix® application
access.
◆
Mobile device access
FirePass server provides email, file, and Intranet access from
mini-browsers on mobile devices. These include Internet-enabled (WAP
and iMode) telephones, PDAs (PalmOS® and Pocket PC), and RIM
Blackberries™.
◆
Administration
FirePass server provide a web–based Administrator Console. The
Console includes tools for installing and managing the FirePass server,
including user and group enrollment and management, clustering and
failover configuration, certificate generation and installation, and user
interface customization.
◆
Audit trail
FirePass server provides audit tools including full-session audit trails,
drill-down session queries, and customizable reports and queries.
◆
Client/Server application support
FirePass server offers a Client-Server Connector™ providing
application-specific tunnels for client-server applications like
Microsoft® Outlook®, ERP package applications, and custom TCP/IP
applications.
FirePass™ Server Administrator Guide1 - 3
FirePass server also provides a VPN Connector™ giving full network
access comparable to that offered by a traditional IPSec VPN connection.
Page 16
Chapter 1
About this guide
◆
Desktop Access
FirePass server offers web–based access to authorized desktops with
support for remote control, lightweight email/file access, guest access,
and Web conferencing.
◆
High availability
FirePass servers can be configured to failover to hot standby servers.
◆
Scalability
FirePass server clusters support up to 10,000 users on a single logical
server.
This FirePass Administrator Guide provides information and step-by-step
instructions for installing and administering the FirePass™ 1000 and 4000
servers.
This guide is available as an Adobe Acrobat file (.pdf). (To install a free
version of Adobe Acrobat Reader, see http://www.adobe.com.)
Audience
This guide is for system and network administrators who install and
configure IT equipment and software. This guide assumes that
administrators have experience installing software and working with
network configurations.
1 - 4
Page 17
Introducing the FirePass Server
Finding help and technical support resources
You can find additional technical documentation about the FirePass server
in the following locations:
◆
Release notes
Release notes containing the latest information for the current version of
FirePass server are available from the Administrative Console. Click the
Maintenance tab and then click the Online Update link. Release notes
include a list of new features and enhancements, a list of fixes, and a list
of known issues.
◆
Online help for FirePass features
You can find help online for virtually all screens on the Administrative
Console. Click the Help Page button in the upper right of the panel.
◆
Technical support through the World Wide Web
®
The F5
provides the latest technical notes, answers to frequently asked questions,
updates for the Administrator Kit (in PDF format), updates for the
release notes, and the Ask F5 natural language question and answer
engine.
Networks Technical Support web site, http://tech.f5.com,
Conventions used in this manual
Information that you type appears in a bold, monospace font. For example:
admin
A Tip suggests ways to make administration easier or faster. For example:
Tip
An easy way to enter a user agent string is to copy and paste the string from
the Logons report.
A Note or Important contains important information. For example:
Note
If you are powering up a server cluster, always power up the master server
first.
Important
If your superuser password is lost, con tact Technical Support.
A Warning describes actions that can cause data loss or problems. For
example:
FirePass™ Server Administrator Guide1 - 5
WARNING
Do not turn the FirePass server off by using the Power switch on the front
panel.
Page 18
Chapter 1
1 - 6
Page 19
2
Deploying the FirePass Server
• Overview of deploying the FirePass server
•Configuring a firewall to work with the FirePass
server
• Understanding name resolution issues for FirePass
servers with a private IP address
• Installing the FirePass server
• Testing network connectivity
• Using the Administrative Console to configure the
FirePass server
• Using the Maintenance Console
• What’s next?
Page 20
Page 21
Deploying the FirePass Server
Overview of deploying the FirePass server
This section contains an overview of the tasks for deploying the FirePass™
server.
Summary of tasks for installing and deploying the FirePass server
Table 2.1 provides a summary of the tasks for installing and deploying the
FirePass server.
TaskFor more information, see
Configure the firewalls at your site to allow traffic to and
from the FirePass server.
If the FirePass server has a private IP address, set up
name resolution for internal users and client software.
Install the FirePass server, and power it up. Using the
WAN port, create an isolated network to reach the
FirePass server using its factory default IP address.
Enter basic configuration information using either the
Administrative Console (recommended) or the
Maintenance Console (available as a backup).
Connect the FirePass server to the network. Test that the
FirePass server is accessible on the network, and test
DNS resolution of the FirePass server’s host name inside
and outside firewall.
After the FirePass server is up and running and the
network connections are working, use the Administrative
Console to finish configuring the server from a Web
browser.
(Recommended) Change the superuser password.Changing the superuser password, on page 2-18
Configure one or more authentication methods for
FirePass users. Then add groups and user accounts.
Configuring a firewall to work with the FirePass server, on
page 2-2
Understanding name resolution issues for FirePass
servers with a private IP address, on page 2-11
Installing the FirePass server, on page 2-12
Using the Administrative Console to configure the
FirePass server, on page 2-17
Testing network connectivity, on page 2-16
Using the Administrative Console to configure the
FirePass server, on page 2-17
Chapter 3, Setting Up FirePass Server Security
Configure the FirePass server’s Webifyers that you want
to make available to users. For example, configure the
SSL VPN Webifyer, if necessary.
Install a new SSL certificate.Setting up certificates, on page 3-29
(Optional) If necessary, customize the appearance of the
user’s home panel, such as the logo and terms used for
logging in.
Table 2.1 Overview of FirePass Deployment Tasks
FirePass™ Server Administrator Guide2 - 1
Chapter 4, Configuring the FirePass Webifyers
Customizing the user’s home page, on page 5-31
Page 22
Chapter 2
Configuring a firewall to work with the FirePass
server
The FirePass server enables remote access by communicating through
secure tunnels between remote users at untrusted or unprivileged hosts on
the Internet and your corporate LAN. This section describes the firewall
ports at your site that must be opened to allow traffic to and from the
FirePass server so that it can operate correctly.
The particular firewall ports that you must open at your site depend on
where you install the FirePass server relative to the firewalls, and which
network and application services the server must access. There are some
ports that must be open in all situations, such as ports 80 and 443 for HTTP
and HTTPS, on the external firewall between the FirePass server and remote
Web browsers. If the FirePass server is installed in a DMZ with an internal
firewall separating it from the corporate network, you also have to open
other ports as necessary to allow access to network services such as DNS,
and to use particular application services such as e-mail.
The illustration in Figure 2.1 shows the services and ports used by the
FirePass server.
.
Figure 2.1 Allowing traffic on firewall ports for a FirePass server
For more information on configuring the firewall ports, see the foll owin g
section and the tables on pages 2-6 through 2-10.
2 - 2
Page 23
Overview of the firewall configuration process
During the process of firewall configuration, you might consider opening
the firewall ports in phases. In the initial phase, you could focus on opening
the ports that allow access to the FirePass server from both inside and
outside the firewall when you specify the server’s host name in a Web
browser. In this initial phase, you might also open the ports for SMTP so
that the FirePass server can send email messages to the FirePass
administrator. For this initial phase, the following ports need to be opened:
• Assuming there is a firewall between the Internet and the FirePass server,
the firewall must allow inbound traffic on ports 80 (HTTP) and 443
(SSH) as a base configuration with a destination address of the publicly
accessible FirePass address.
• The firewall must also allow the FirePass server access to network
services such as NTP, DNS, and SMTP (on ports 123, 53, and 25). The
network services might be located on an external network (Internet), or
on the internal corporate network. The location of the network services
and your particular deployment scenario determines which firewall’s
ports must be open, assuming there is a firewall between the FirePass
server and these services.
• If there is a firewall between the FirePass server and the corporate LAN,
the firewall must allow traffic on ports 80, 443, and 661.
Deploying the FirePass Server
To verify that the FirePass server has access to DNS and SMTP services
after you have opened the ports and installed the FirePass server, you can
use the instructions in Testing network connectivity, on page 2-16.
After you have verified that the FirePass server has access to DNS and
SMTP services and that you can access the server from a Web browser from
either side of the firewall, then you can open up the specific ports that are
necessary for your particular deployment. See the following tables in this
section that describe the ports and services. For example, if you are using
LDAP for authentication, you must open ports 389 and 636. Here are some
other examples of application services you might need to support:
• To support My Files, the FirePass server needs access to Windows file
servers using Microsoft Networking (ports 135, 137, 138, 139).
• To support My Email, the FirePass server needs access to POP/IMAP
and LDAP (ports 110, 143, 389, 636).
• To support Host Access, the FirePass server needs access to Telnet (port
23).
The services are sometimes hosted locally behind a firewall, and sometimes
hosted remotely. If the services are hosted remotely, the external firewall
must allow the FirePass server to make connections to those services on
specific TCP/IP ports.
To allow access to the FirePass server from the Internet, you can create
either Network Address Translation (NAT) rules or port forwarding rules on
the firewall to forward inbound packets to the server. The advantage of
static NAT is that it does not require you to forward each individual port to
FirePass™ Server Administrator Guide2 - 3
Page 24
Chapter 2
the FirePass server. To use static NAT, configure a rule that forwards all
allowable traffic from the public IP address to the private IP assigned to the
FirePass server. However, some firewalls only allow static NAT using a
public IP address other than its own public interface. In this case, you must
use port forwarding by setting up rules to forward the appropriate ports to
the private IP address assigned to the FirePass server.
Firewalls can be classified as stateful and non-stateful. Stateful firewalls
allow bi-directional communication (that is, they create a return rule for an
allowed service). Older firewalls, especially ones based on Linux IP chains,
are often non-stateful; they do not allow bi-directional communications. If
you have a stateful firewall (most newer commercial firewalls are stateful),
you only need to define rules for the actual traffic; the replies are
automatically allowed to pass. If you have a non-stateful firewall, you also
must define rules for traffic coming in and the replies with the ACK
(acknowledgement) bit set for those protocols.
For completeness, the following tables list the types of traffic (in pairs of
request and response) that must be allowed through the firewalls for each
category of FirePass server functionality.
All traffic associated with the FirePass server falls into in one of these
categories:
• Traffic between the remote user’s browser and the FirePass server. (See
About the traffic between a remote user’s browser and the FirePass
server, on page 2-5.)
• Traffic between the FirePass server and network services, such as LDAP,
RADIUS, and DNS. (See About the traffic between the FirePass server and network services, on page 2-6.)
• Traffic between the FirePass server and application services, such as file
servers, email servers, and the Intranet. (See About the traffic between FirePass server and application services, on page 2-7.)
• Traffic between the FirePass server and corporate LAN using My
Desktop. (See About the traffic between the FirePass server and the Desktop Agent, on page 2-9.)
2 - 4
Note
A particular type of traffic shown in the tables is only required if Required
appears in the Comment column for the traffic, or, as stated previously, if
you are enabling an application service that requires the port to be opened.
Page 25
Deploying the FirePass Server
About the traffic between a remote user’s browser and the
FirePass server
To allow traffic between a remote user’s browser and the FirePass server,
you must open the firewall ports as shown in Table 2.2.
The FirePass bridge ports (10000-10100) are optional ports in the external
firewall that are used to distribute sessions to ensure that port 443 is open for
new requests. These ports are configurable, and can be set to any of the high
TCP/IP ports (1025 – 65535). If the number of concurrent My Desktop users
is low—less than 5 concurrent users on the FirePass 1000, or less than 20 on
the FirePass 4000—then there is no requirement to open the high TCP/IP
ports (1025 to 65535). The server uses the high ports if they are available,
otherwise it uses port 443.
During installation, or in case of severe malfunction, you may need to give
Technical Support access to your Maintenance Console using Secure Shell
(SSH). To allow this access while blocking routine SSH access, the FirePass
server provides temporary, encrypted keys, further protected by a
passphrase. For more information about providing SSH access to Technical
Support, see Providing SSH access for Technical Support, on page 5-31.
SourceDestination
Traffic TypeProtocol
HTTPTCPRemote
HTTP
(response)
HTTPSTCPRemote
HTTPS
(response)
FirePass
bridge
FirePass
bridge
Response
SSHTCPLocal LAN1025 to
TCPFirePass
TCPFirePass
TCPRemote
TCPFirePass
Browser
server
Browser
server
Browser
server
1025 to
65535
80Remote
1025 to
65535
443Remote
1025 to
65535
10000 to
10100
65535
FirePass
server
Browser
FirePass
server
Browser
FirePass
server
Remote
Browser
FirePass
server
Ack
bit
80Required
1025 to
65535
443Required
1025 to
65535
10000 to
10100
1025 to
65535
22Optional
yesRequired
yesRequired
yesOptional for
CommentAddressPortsAddressPorts
Optional for
My Desktop
My Desktop
SSH
(response)
TCPFirePass
Table 2.2 Traffic between a remote user’s browser and the FirePass server
FirePass™ Server Administrator Guide2 - 5
server
22Local LAN1025 to
65535
YesOptional
Page 26
Chapter 2
About the traffic between the FirePass server and network
services
The FirePass server needs access to the network services listed in Table 2.3,
some of which are optional and depend on your particular configuration. If
the services are hosted across a firewall from the FirePass server, you must
open the firewall ports to allow the FirePass server to access these services.
Important
Configure your internal DNS server such that your FirePass server host
name resolves to the server’s local IP address. This is to ensure that traffic
from the same side of the firewall can reach the FirePass server. You can do
this on a WINS server or on a DNS server if the DNS server is hosted
locally. (See Understanding name resolution issues for FirePass servers with a private IP address, on page 2-11.)
SourceDestination
Traffic TypeProtocol
DNSTCPLocal LAN1025 to
DNS (response)TCPFirePass
server
NTPUDPLocal LAN1025 to
NTP (response)UDPFirePass
SSHTCPLocal LAN1025 to
SSH (response)TCPFirePass
SecurID
authentication
SecurID
authentication
(response)
TCPFirePass
TCPLocal LAN1645, 1646FirePass
server
server
server
65535
53Local LAN1025 to
65535
123Local LAN1025 to
65535
22Local LAN1025 to
1025 to
65535
FirePass
server
FirePass
server
FirePass
server
Local LAN1645,
server
53
65535
123
65535
22Optional
65535
1646
1025 to
65535
Ack
bit
Yes
YesOptional
YesOptional
CommentAddressPortsAddressPorts
Optional
LDAPTCPFirePass
LDAP (Response)TCPLocal LAN389, 636FirePass
Table 2.3 Traffic between FirePass server and network services
2 - 6
server
1025 to
65535
FirePass
server
server
389,
636
1025 to
65535
Required for
LDAP
authentication
YesRequired for
LDAP
authentication
Page 27
Deploying the FirePass Server
Traffic TypeProtocol
RADIUSTCPFirePass
server
RADIUS
(response)
SMTP ServicesTCPFirePass
SMTP Services
(response)
TCPLocal LAN1645, 1646FirePass
server
TCPLocal LAN25FirePass
SourceDestination
1025 to
65535
1025 to
65535
Local LAN1645,
1646
1025 to
server
Local LAN25
server
65535
1025 to
65535
Ack
bit
YesRequired for
Yes
CommentAddressPortsAddressPorts
Required for
RADIUS
authentication
RADIUS
authentication
Table 2.3 Traffic between FirePass server and network services (Continued)
About the traffic between FirePass server and application services
To allow traffic between the FirePass server and application services on the
corporate LAN, you must open the firewall ports as shown in Table 2.4. The
application services include the following services, some of which are
optional and depend on your particular configuration:
• File servers
•Email servers
• Intranet
• Terminal servers
• Legacy mainframe and AS/400 applications
• Client/server applications
•SSL VPN
FirePass™ Server Administrator Guide2 - 7
A FirePass server that needs to use any of these application services must be
able to communicate with the local LAN on several ports. Most of these
ports are listed in Table 2.4 with the default port assignments. (Your
network may vary). Microsoft Networking requires four ports, two TCP/IP
ports and two UDP ports. Port 135 is the RPC port, port 139 is the NetBIOS
session, port 137 is the NetBIOS name service, and port 138 is the datagram.
These ports must be configured to allow users to use the My Files Webifyer
to view network file shares. A WINS server helps address resolution from
NetBIOS to TCP/IP to work properly.
Page 28
Chapter 2
SourceDestination
Traffic TypeProtocol
HTTPTCPLocal LAN1025 to 65535FirePass
server
HTTP
(response)
HTTPSTCPLocal LAN1025 to 65535FirePass
HTTPS
(response)
IMAPTCPFirePass
IMAP
(Response)
POPTCPFirePass
POP
(Response)
TCPFirePass
server
TCPFirePass
server
server
TCPLocal LAN143FirePass
server
TCPLocal LAN110FirePass
80Local LAN1025 to
server
443Local LAN1025 to
1025 to 65535Local LAN143Required for
server
1025 to 65535Local LAN110Required for
server
Ack
bit
80Required
YesRequired
65535
443
Yes
65535
1025 to
65535
1025 to
65535
YesRequired for
YesRequired for
CommentAddressPortsAddressPorts
email
email
email
email
Microsoft
Networking
Microsoft
Networking
(Response)
Microsoft
Networking
Microsoft
Networking
(Response)
Telnet/3270TCPFirePass
Telnet/3270
(Response)
Client/Server
applications
TCPFirePass
server
TCPLocal LAN135, 139FirePass
UDPFirePass
server
UDPLocal LAN137, 138FirePass
server
TCPLocal LAN23FirePass
TCPFirePass
server
1025 to 65535Local LAN135, 139Required for
server
1025 to 65535Local LAN137, 138Required for
server
1025 to 65535Local LAN23Required for
server
1025 to 65535Local LANUser-defin
Table 2.4 Traffic between FirePass server and application services
1025 to
65535
1025 to
65535
1025 to
65535
ed TCP
File services
YesRequired for
File services
File services
YesRequired for
File services
Host Access
YesRequired for
Host Access
Required for
each App
tunnel
2 - 8
Page 29
Deploying the FirePass Server
Traffic TypeProtocol
Client/Server
applications
(response)
SSL VPN
Connector
SSL VPN
Connector
(response)
TCPLocal LANUser-defined
TCP
UDP
ICMP
TCP
UDP
ICMP
SourceDestination
TCP
FirePass
server
Local LANAny ports as
1025 to 65535Local LANAny ports
needed
FirePass
server
FirePass
server
1025 to
65535
as needed
1025 to
65535
Ack
bit
YesRequired for
YesRequired for
CommentAddressPortsAddressPorts
each App
tunnel
Required for
SSL VPN as
needed
SSL VPN as
needed
Table 2.4 Traffic between FirePass server and application services (Continued)
About the traffic between the FirePass server and the Desktop
Agent
To allow traffic from the FirePass server to the corporate LAN using the My
Desktop feature, you must open firewall ports as shown in Table 2.5.
The FirePass client on the desktop computer on the local LAN uses ports 80
and 81 to initiate communications with the FirePass server during My
Desktop sessions. The FirePass server “wakes” the client on port 661, then
communicates with it on port 443. The client then initiates a new connection
on port 81 back to the FirePass server.
Host Activation Protocol (HAP) is a registered port (661) which allows the
FirePass server to initiate a session with the FirePass Desktop Agent. The
FirePass server communicates with the Agent on port 443.
Note
The port numbers in the following table are default values which you can
change. For more information, see Configuring the My Desktop Webifyer,
on page 4-31.
FirePass™ Server Administrator Guide2 - 9
Page 30
Chapter 2
SourceDestination
Traffic TypeProtocol
HTTPTCPLocal LAN1025 to 65535FirePass
server
HTTP
(response)
Host Activation
Protocol (HAP)
Host Activation
Protocol (HAP)
(response)
HTTPSTCPFirePass
HTTPS
(response)
TCPFirePass
server
TCPFirePass
server
TCPLocal LAN661FirePass
server
TCPLocal LAN443FirePass
80, 81Local LAN1025 to
1025 to 65535Local LAN661Required for My
server
1025 to 65535Local LAN443
server
80, 81Required for My
65535
1025 to
65535
1025 to
65535
Table 2.5 Traffic between FirePass server and corporate LAN using My Desktop
Ack
bit
YesRequired for My
YesRequired for My
Yes
CommentAddressPortsAddressPorts
Desktop
Desktop
Desktop
Desktop
2 - 10
Page 31
Deploying the FirePass Server
Understanding name resolution issues for FirePass
servers with a private IP address
If the FirePass server is installed on a corporate LAN or in a DMZ that uses
private IP addresses, the firewall or gateway performs Network Address
Translation (NAT). This means that the FirePass server has two different
DNS “identities”—one mapped to the public IP address, and another one to
the NAT'ed private IP address.
External users outside the firewall do not have name resolution problems
because the FirePass server’s name resolves to the public address of the
firewall or gateway. The firewall or gateway then forwards the user’s traffic
to the FirePass server.
However, internal users on the corporate LAN and the My Desktop client
software can be affected by internal name resolution problems unless you
prevent them. You can prevent name resolution problems by doing any of
the following:
◆
If you have an internal DNS server, set up a zone with a fully qualified
domain name (such as server-name.company.com), and then add an A
record to that zone that resolves to the FirePass server’s private address
(such as 10.0.0.8).
◆
If you have a WINS server, add a static entry for the FirePass server
name.
◆
If you have a firewall that supports a DNS alias feature (such as the
CISCO PIX), set up the firewall to redirect internal FirePass server
traffic originating from the corporate LAN to the FirePass server’s
private IP address.
◆
If there is no internal DNS server, WINS server, or suitable firewall, you
must use a local hosts file on each corporate LAN computer that must
connect to the FirePass server.
Note
This name resolution problem does not apply to a FirePass server that has a
public IP address because internal and external users can both use a name
that resolves to the same IP address for the server.
Important
To support the FirePass server’s application tunnels for clustered or load
®
balanced applications such as Oracle
, Citrix®, or SAP®, you must specify
the fully qualified domain names of the servers running the applications.
Those applications must also support the use of fully qualified domain
names when passing server address information to the client side
application. Single server applications may use the server IP address if the
remote client is also configured to do so.
FirePass™ Server Administrator Guide2 - 11
Page 32
Chapter 2
Installing the FirePass server
This section describes how to install one or more FirePass servers in an
equipment rack, connect them to a network, and power them up.
When installing and connecting wiring to the FirePass server, be sure to
follow these basic safety precautions to avoid injury to you or damage to the
server:
• Read and understand all instructions.
• Do not disassemble the FirePass server.
• Do not restrict airflow through the fans or vents of the FirePass server.
• Connect the unit to a properly grounded and rated power supply circuit
that meets the provisions of the current edition of the National Electrical
Code, or other wiring rules that may apply to your location.
Unpacking the FirePass server
After unpacking the FirePass server, you should have the following items:
• FirePass server
• 120 VAC power cord
• Network cable
Installing the FirePass server in an equipment rack
Install a FirePass 1000 server in a standard 1U equipment rack, and a
FirePass 4000 server in a standard 2U equipment rack. Make sure that the
rack has adequate ventilation and power. We strongly recommend using an
Uninterruptible Power Supply (UPS).
Connecting the FirePass server to a network and powering up
To connect a FirePass server to a network and power up:
1. Connect an Ethernet cable from your network to the 10/100 Base-T
(RJ-45) WAN connector on the FirePass server.
• FirePass 1000: the WAN port is clearly labeled on the front panel
of the server.
2 - 12
• FirePass 4000: the WAN port is on the back of the server. It is the
network port in the expansion slot on the right side (see FirePass 4000 port locations, on page 2-13).
Page 33
Deploying the FirePass Server
Figure 2.2 FirePass 4000 port locations
2. If you are connecting two dual-NIC FirePass servers in failover
pairs, connect the same corresponding NICs to the same subnet on
both servers. For example, connect the internal NIC on both servers
to the same subnet. For information on configuring FirePass failover
servers, see Chapter 7, Configuring FirePass Failover Servers and Cluster Servers.
3. If you are connecting several FirePass servers as a cluster, connect
the primary NICs to the same subnet unless they are installed in
different geographic locations. For information on configuring
FirePass server clusters, see Using FirePass server clusters, on page
7-5.
4. Plug in the power cable into a 120 VAC wall outlet and into the
Power connector on the rear panel of the FirePass server.
5. Turn on the Power switch on the front panel of the FirePass server.
Note
If you are powering up a server cluster, always power up the Master server
first. If the Master server is not available when the slave servers power up,
then the cluster does not work properly.
WARNING
Do not turn the FirePass server off by using the Power switch on the front
panel. Data corruption might occur, possibly rendering the FirePass server
unavailable. To shut the FirePass server down, always use the Shutdown
commands in the Administrative Console or the Maintenance Console. For
more information, see Shutting down and restarting FirePass, on page
5-17.
FirePass™ Server Administrator Guide2 - 13
Page 34
Chapter 2
Performing the initial FirePass IP configuration
The FirePass server comes pre-configured with a default set of networking
and server settings. The following table provides important default FirePass
settings.
SettingFactory default value
Admin Console User Nameadmin
Admin Console passwordadmin
Maintenance Console User Namemaintenance
Maintenance Console password<no password>
Server namefirepass.company.xyz
Server IP Address/Mask192.168.1.99 / 255.255.255.0
Perform the initial IP configuration using the web-based FirePass
Administrative Console interface (recommended) or the terminal-based
FirePass Maintenance Console.
To use the web-based Administrative Console for initial
configuration (recommended)
2 - 14
1. Create an isolated network that includes the FirePass server and
another machine with a web browser. Connect them directly using a
cross-over Ethernet cable, or indirectly with a standard Ethernet
cable and an isolated hub or switch. Enter the default URL,
Page 35
Deploying the FirePass Server
https://192.168.1.99/stats/ into the web browser (be sure to include
the final slash). One or more certificate warning messages may be
displayed. Accept these. You should see the FirePass login screen.
2. Login using the default administrator name admin and password of
admin.
3. Set up the IP configuration. Navigate to
Server/Maintenance/Network Configuration. Specify the IP address,
subnet, and port settings. For more information see Maintaining the network configuration settings, on page 5-1.
4. DNS name resolution. Navigate to Server/Maintenance/Network
Configuration/Hosts. Enter the fully-qualified domain name
(FQDN) of your FirePass server and the IP Address of your Domain
Name Server. If you have not already done so, make the
corresponding entries in your Domain Name Server.
5. Shutdown/restart. Now shut down and restart FirePass. For more
information see Shutting down and restarting FirePass, on page
5-17.
6. Connect to your network. Disconnect the FirePass server from the
isolated network and reconnect it to your network. Test the network
connections by following the instructions in Testing netwo rk connectivity, on page 2-16.
7. Finish configuring your FirePass server following the steps in
What’s next?, on page 2-23.
To use the terminal-based Maintenance Console for initial
IP configuration
First see To use the Maintenance Console to configure the FirePass server,
on page 2-21.
1. Configure the appropriate network settings for your environment.
2. Shut down and restart the FirePass server.
3. Login to the Administrator’s Console, and then finish configuring
the FirePass server following the steps in What’s next?, on page
2-23.
Note
You can also access the Maintenance Console using a Telnet session in the
Administration Console. For more information, see Using the Administrative Console to configure the FirePass server, on page 2-17.
FirePass™ Server Administrator Guide2 - 15
Page 36
Chapter 2
Testing network connectivity
After connecting the FirePass server to your network, powering it up , and
performing the initial IP address configuration, test that you can access the
server from your network, and that the FirePass server’s fully qualified
domain name resolves correctly both inside and outside the firewall.
To test network connectivity:
1. Test that the FirePass server is accessible from the LAN by entering
the following command on a host computer on the LAN:
ping x.x.x.x
where x.x.x.x is the FirePass server’s private IP address.
2. Test DNS resolution of the FirePass server’s name and address
inside the firewall. On a host computer inside the firewall, enter the
following command:
ping <fully qualified server name>
Inside the firewall, this name should resolve to the FirePass server’s
private IP address.
3. Test DNS resolution of the FirePass server’s name and address
outside the firewall. On a host computer outside the firewall, enter
the following command:
ping <fully qualified server name>
Outside the firewall, this name should resolve to the FirePass
server’s public IP address.
Note: You may not receive pings back from outside the firewall if
the firewall is not configured to pass ICMP packets.
4. Test accessing the server from a Web browser by entering the URL
for the FirePass server on computers both inside and outside the
firewall. For example, enter:
https://<host name of FirePass>/stats/
where <host name of FirePass> is the host name assigned to the
FirePass server. For example, enter:
https://server-name.company.com/stats/
The FirePass server’s login screen should appear when you enter
this URL.
Use the following information to troubleshoot problems accessing the
server:
◆
If you have trouble accessing the FirePass server with a Web browser on
a computer outside the firewall, the problem is usually caused by a
misconfigured firewall, or a firewall that does not allow packets to travel
in both directions. Non-stateful firewalls do not keep a connection state
history table and cannot identify packets returning from an open
connection unless a similar rule looking for an ACK bit is configured to
allow traffic to go in the opposite direction.
2 - 16
Page 37
Deploying the FirePass Server
◆
If you have trouble accessing the FirePass server by entering the fully
qualified domain name on a computer inside the firewall, try entering the
internal IP address. This problem is usually caused by DNS reflection,
which occurs when an internal host sends a packet to the external
interface of the firewall. When the firewall forwards the packet to the
FirePass server, the FirePass server replies to the external interface of the
firewall which cannot properly route the packet back to the internal host.
Some routers have a work-around for this problem.
Using the Administrative Console to configure the
FirePass server
After verifying that the FirePass server is accessible on your network, you
can use the Administrative Console in a Web browser to administer the
server and change configuration settings as necessary. You can run the
Administrative Console on any computer that can access the FirePass server
over the network.
Logging Into the Administrative Console
To log into the Administrative Console:
1. Enter the following URL in a Web browser on a computer that can
access the FirePass server over a network or the Internet:
https://<host name of FirePass>/stats/
where <host name of FirePass> is the host name assigned to the
FirePass server. For example, enter:
https://server-name.company.com/stats/
2. If a Security alert appears, click Yes to accept the SSL encryption
certificate.
The FirePass login screen appears. (See below.)
3. Enter the following superuser user name: admin.
4. Enter the default superuser password: admin.
Note: The user name and password are case sensitive. If the
FirePass server rejects the user name and password, contact
Technical Support.
FirePass™ Server Administrator Guide2 - 17
Page 38
Chapter 2
5. Click Login.
.
After you log in, the Welcome panel for the FirePass Administrative
Console appears. The Administrative Console is composed of several panels
where you select options, enter configuration information, and choose
commands to configure and administer the FirePass server. Some panels
contain status information and reports that you can use to monitor the server.
Click the tabs and links on the left side of the display to load each screen on
the right side.
Changing the superuser password
One of the first tasks you should do is change the default password for the
preconfigured Administrator (“superuser”) account.
To change the superuser password
1. Under the Server tab on the left side of the Administrative Console,
click the Security link.
2. Click the Password link.
The Change Superuser Password screen opens.
3. In the Old Password text box, type the current password.
4. In the Password and Confirm Password text boxes, type the new
password, and then click Go.
Important
You also see an option to disable the Superuser account. Do not check this
option before you have given comprehensive Administrator privileges,
including access to all links on the Server tab, to other named accou nts.
You can assign Administrator privileges to other users by navigating to
2 - 18
Page 39
Server/Security/Administrators. For more information about assigning
Administrator privileges, see Granting Administrator privileges to other users, on page 5-21.
If your superuser password is lost, con tact Technical Support.
Installing your license
Getting your first license
Your server should already have an installation type, serial number and
registration key assigned. These show as the first three items in the Settings
table display. If the Serial number is shown as unknown, contact Technical
Support.
When you receive your new FirePass server, you should also have received
an email from Technical Support or the entitlement server. If so, follow the
directions in the email. If not, contact Support ([email protected]) to make
sure your license is ready.
Deploying the FirePass Server
Important
Licenses are time-limited, for security reasons. Install your license as soon
as you receive it.
Make sure that your firewall allows outbound Internet connections to port
443.
Navigate to Server/Settings. Then click on the Pick up new license... link. If
your license is ready and the server can contact the licensing server, your
new license is installed.
Adding capacity or features to your license
To add session capacity or features, see Adding capacity or features to your
license, on page 5-11.
Displaying a list of current settings and licensed features
You can display a list of the current configuration settings and licensed
features. To display a list of current settings and licensed features click the
Settings link under the Server tab. These are read-only, and are offered to
assist in troubleshooting.
FirePass™ Server Administrator Guide2 - 19
Page 40
Chapter 2
Using the Administrative Console to access the Maintenance
Console
You can use a web browser to gain access to the Maintenance Console. You
do this by launching a Telnet session within the Administrative Console.
To use the Administrative Console to run the Maintenance
Console
1. Under the Server tab on the left side of the Administrative Console,
click the Maintenance link.
The Maintenance screen opens.
2. Click the Low-level link.
3. Under Telnet access, click the Telnet Session to the Maintenance Account link.
4. At the Login prompt, enter the following:
No password is required.
5. Enter
Y
to agree to the conditions on the screen.
The Maintenance Console menu appears.
Logging out of the Administrative Console
If you do not log out of the Administrative Console, the FirePass server
automatically times you out after a period of inactivity. This time interval is
specified in the Inactivity Timeout option on the Customization panel of the
Administrative Console.
To log out of the Administrative Console
Use either option:
• Click the Logout link on the left side of the Administrative Console.
• Close your Web browser.
maintenance
.
2 - 20
Page 41
Using the Maintenance Console
If you intend to use the Administrative Console web interface
(recommended) to configure the FirePass IP address or if your server’s IP
address and network mask are already configured correctly, you can skip
this section.
However, if your server’s IP address and network mask are not configured
correctly, or if you are unable to connect to the server using a Web browser
on the network, you can use the Maintenance Console to make configuration
changes according to the instructions in this section. You can also use the
Maintenance Console to perform basic connectivity diagnostics.
Use one of the following methods to access the server and run the
Maintenance Console:
• Connect another computer’s serial port to the FirePass server’s serial
port, and then use a terminal emulation program.
• Connect a monitor and keyboard directly to the FirePass server (FirePass
4000 only).
Deploying the FirePass Server
To use the Maintenance Console to configure the FirePass
server
1. Use a 9-pin D-style, null modem cable to connect the serial port on
a serial terminal or on a computer to the FirePass server’s serial
console port on the server’s rear panel.
2. If necessary, turn on the FirePass server’s Power switch.
3. Do one of the following:
• If you connected a serial terminal, press Enter on the terminal’s
keyboard to start the Maintenance Console.
• If you connected a computer to the serial port, start a serial
terminal emulation application (such as HyperTerminal on
Windows
terminal emulation application to connect to the FirePass server
with the following communications settings:
SettingValue
Bits per second9600
Data bits8
ParityNone
®
or Minicom on Linux) on the computer. Use the
FirePass™ Server Administrator Guide2 - 21
Stop bits1
Flow controlXon/Xoff
Page 42
Chapter 2
4. At the Login prompt, enter the following: maintenance
No password is required.
5. Enter
Y
to agree to the conditions on the screen.
The Maintenance Console menu appears.
6. To change the server name or other network settings, enter 1 for
Network Configuration and then press the Enter key.
Tip
The IP Address and Network Mask are the only settings that you must
configure to enable access to the server using the Administrative Console
running in a Web browser on the network. But you can also use the other
Maintenance Console commands at a later time to configure other settings.
7. At the Network Configuration prompts, enter the appropriate
information or press the Enter key to accept the current setting.
8. After you finish entering the settings, enter
Y
at the confirmation
prompt.
9. For some configuration changes, the server prompts you to restart.
• To restart the server, enter 6 for Restart Server on the command
menu, and then press the Enter key.
• Otherwise, enter 8 for Exit, and then press the Enter key to exit
the Maintenance Console.
10. Disconnect the serial cable.
2 - 22
Page 43
What’s next?
Deploying the FirePass Server
Now that the FirePass server is installed and accessible on the network, you
can use the Administrative Console to finish configuring FirePass.
◆
Set up security on the FirePass server by adding groups and user
accounts, and then configuring authentication. For more information, see
Chapter 3, Setting Up FirePass Server Security.
◆
(Optional) If necessary, change the FirePass server host name to a name
that is appropriate for your site. For more information, see Changing the FirePass server name, on page 3-30.
◆
Install a new SSL certificate. For more information, see Setting up
certificates, on page 3-29.
◆
Configure the SMTP Server, Administrator’s password and email,
proxies, and SSL Server Certificate. See Chapter 5, Managing, Monitoring, and Maintaining the FirePass Server, for directions.
◆
Install the license signature. You may have received an email from the
F5 entitlement server describing how to install your license. If so, use
those directions. If not, contact technical support ([email protected]) to
make sure your license is ready. Then navigate to
Server/Settings/License and click on the link to pick up your new license
signature.
◆
Configure the Webifyers that you want to make available to users. For
example, configure the SSL VPN Webifyer, if necessary. For more
information, see Chapter 4, Configuring the FirePass Webifyers.
◆
(Optional) If necessary, customize the appearance of the user’s home
page, such as the logo and terms used for logging in. For more
information, see Customizing the user’s home page, on page 5-31.
Note
After you use the superuser account to create user accounts, you can assign
administrative privileges to one or more user accounts. For more
information, see Assigning administrative privileges to a user account, on
page 3-19.
FirePass™ Server Administrator Guide2 - 23
Page 44
Chapter 2
2 - 24
Page 45
3
Setting Up FirePass Server Security
• Overview of setting up FirePass server security
• Working with groups
• Working with user accounts
• Setting up FirePass server authentication
• Setting up certificates
• Limiting access to the administrative console by IP
address
• What’s next?
Page 46
Page 47
Setting Up FirePass Server Security
Overview of setting up FirePass server security
Here is an overview of the steps for setting up groups, user accounts,
authentication, and certificates on the FirePass™ server.
1. (Optional) If you want to use different settings for different users,
create one or more additional groups on the FirePass server.
Otherwise, use the default group for all users.
Authentication, Webifyers, and many other features are set up on a
per group basis on the FirePass server. If you are using the same
authentication and Webifyer settings for all FirePass server users,
you can simply add all users to the preexisting default group and use
the default group for all settings. But if you want to use different
authentication and Webifyer settings for different users, you must
create one or more additional groups on the FirePass server before
adding users or setting up authentication. (See Working with groups,
on page 3-2.)
2. (Optional) If the FirePass server users are stored in an LDAP or a
Windows Domain server, you can set up group mapping.
Group mapping automatically keeps the groups on the FirePass
server synchronized with the groups on the Windows Domain server
or LDAP server. That is, if a user is moved to a different group on
the Windows Domain or LDAP server, FirePass server
automatically moves the user to the corresponding mapped group in
its internal database the next time the user logs into FirePass server.
If you also choose to use a signup template for new FirePass server
users, group mapping can also have FirePass server query a
Windows Domain or LDAP server for each user’s group
membership, and automatically add the new user to the mapped
group in the FirePass server’s internal database. (See Using
Windows domain-based group mapping, on page 3-4 and Using
LDAP-based group mapping, on page 3-6.)
3. Add user accounts to each group on the FirePass server by using any
of the following methods:
• Manually add users to each group. (See Manually adding user
accounts, on page 3-11.)
• Import users into each group from a Windows Domain server, an
LDAP server, or a text file. (See page 3-13 through page 3-16.)
• Enable a signup template for each group to automatically add
users when they log in for the first time if the users have an
existing account in a RADIUS, LDAP, or Windows Domain
server. (See Using signup templates to add user accounts, on
page 3-16.)
FirePass™ Server Administrator Guide3 - 1
All of these methods create user accounts in the FirePass server’s
internal database.
Page 48
Chapter 3
4. (Optional) If you want to give FirePass server users access to NFS
file servers, you can import the NFS permissions for each user that
is listed in a UNIX password file. (See Using NFS user permissions from a UNIX password file, on page 3-17.)
5. Set up authentication for each group on the FirePass server.
You can have the FirePass server use its own internal database for
authentication, or you can have it use an external RADIUS,
Windows Domain, LDAP, or VASCO server for authentication.
(See Setting up FirePass server authentication, on page 3-23.)
6. (Optional) Set up server certificates specifically for your site, and
set up client certificates to validate clients.
If the FirePass server is a pilot deployment, we preinstalled a server
certificate that contains a server-name.FP.com URL. You can
change the FirePass server name to one that is appropriate for your
site, and then generate and install a new server certificate that uses
the new server name.
You can also install an optional client root certificate and optional
certificate revocation list (CRL), and configure the FirePass server
to validate client certificates installed at each user’s computer. You
can use the client certificates as part of a two-factor authentication
system, or to limit access to particular FirePass Webifyers.
For more information on changing the server name and setting up
server and client certificates, see Setting up certificates, on page
3-29.
Working with groups
Users, authentication methods, Webifyers, and other features are set up
separately for each Group defined in FirePass server. If you are using the
same authentication and Webifyer settings for all FirePass server users, you
can simply add all users to the preexisting FirePass server default group and
use the default group for all settings.
But if you want to use different authentication and Webifyer settings for
different users, you must create groups on the FirePass server before adding
users or setting up authentication requirements. For example, you can create
one group of users that uses RADIUS server authentication, and another
group that uses LDAP authentication.
Note
Group IDs for NFS users are not related to FirePass server groups. For
more information, see Using NFS user permissions from a UNIX password file, on page 3-17.
3 - 2
Page 49
Creating groups
Setting Up FirePass Server Security
To create a group
Use the Group Management screen.
FirePass™ Server Administrator Guide3 - 3
1. Under the Users tab on the left side of the Administrative Console,
click the Groups link.
The Group Management screen opens.
2. In the New group name box in the Create New Group section, enter
a name for the group.
Only alphanumeric symbols are allowed.
3. From the Copy settings from list, select the group whose settings
you want to copy to the new group.
All settings for authentication methods, Webifyers, and signup
templates are copied from the selected group to the new group.
Page 50
Chapter 3
4. Click the Create button.
The new group is now accessible from the Group list on the panels
for setting up authentication methods, Webifyers, and signup
templates.
Deleting groups
To delete a group
1. In the Delete Group section of the Group Management panel, select
the group from the Group to Delete drop-down list.
2. From the Reassign Users to drop-down list, choose the group to
which you want to reassign the users from the deleted group.
3. Click the Delete button.
Moving users to a different group
If you are not using group mapping for a group, you can move users to a
different group.
To move users to a different group
1. In the Move Users section of the Group Management panel, select
the group from the Move Users to Group drop-down list to which
you want to move users.
2. Click the Select Users button.
3. In the Move Users panel, select the users you want to move by
clicking the check box next to each name.
4. Click the Move To Group button.
Showing a list of all users in a group
To show a list of all users in a group
1. In the Show Users section of the Group Management panel, select
the group from the Show All Users in a Group drop-down list.
2. Click the Go button.
Using Windows domain-based group mapping
3 - 4
Typically, there are multiple groups defined within a Windows domain and
users belong to one or more of these groups. To use the group membership
information from the Windows domain, you can map the Windows domain
Page 51
Setting Up FirePass Server Security
groups to existing FirePass server groups. When a user logs into the
FirePass server, FirePass server queries the Windows domain groups for the
user’s name and attempts to match one of the domain groups to the FirePass
server’s configured mapping. The FirePass server then dynamically moves
the user to the FirePass server group based on a match. Note that the group
must already exist on the FirePass server and be mapped before the user logs
in. If the user is moved to a Windows domain group that does not exist on
the FirePass server, the user remains in the same FirePass server group.
Because a user can belong to more than one group within a Windows
domain, the first group mapping match is used to determine which FirePass
server group to move the user into. FirePass server uses the order in which
you create mappings to determine the order in which to check for matches.
That is, the first mapping you create is checked first. Keep this in mind
when mapping groups to make sure domain users are mapped properly.
To use Windows domain-based group mapping
1. In the LDAP and Windows Domain Based Grouping section of the
Group Management panel, select the Use Windows Domain Group to Map Group option.
2. In the Domain Name box, specify the name of the Windows
domain you want to map users against.
3. (Optional) In the PDC Server Name box, specify the name of the
Primary Domain Controller (PDC) server if the domain or PDC is
on a different subnet than the FirePass server.
4. (Optional) In the WINS Server IP Address box, specify the IP
address of the WINS server if the domain or PDC is on a different
subnet than the FirePass server.
5. If the Windows domain PDC is not configured to accept anonymous
access to user and group information, click the Join Windows Domain option. Then specify the Domain Admin Name and
Domain Admin Password.
6. Click the Retrieve Windows D omain Group s button to retrieve the
available domain groups from the Windows domain. If an error
message is displayed or the list under Windows Domain Group is
empty, verify the domain settings you specified.
7. To add mappings between domain groups and FirePass server
groups, select domain group entries under the Windows Domain
Group heading. Then select FirePass server groups from the
drop-down list under the Map to Group heading and click the Add Mapping button.
FirePass™ Server Administrator Guide3 - 5
Page 52
Chapter 3
8. To test which FirePass server group a user woul d be mapped to,
enter a user login name for the Windows domain, and then click the
Test Mapping button.
Note
If necessary, you can delete a mapping by selecting it and then clicking the
Delete link.
Using LDAP-based group mapping
LDAP-based group mapping automatically keeps the groups on the FirePass
server synchronized with the groups on an LDAP server. That is, if a user is
moved to a different group on the LDAP server, FirePass server
automatically moves the user to the new group in its internal database the
next time the user logs into FirePass server. If the user is moved to an LDAP
group that does not exist on the FirePass server, the user remains in the same
FirePass server group.
If you use a signup template for new FirePass server users, group mapping
can also have FirePass server query a LDAP or Windows Domain server for
each user’s group membership, and automatically add the new user to the
mapped group in FirePass server’s internal database. (For more information
on LDAP configuration, see Setting up LDAP server authentication, on page
3-27.)
There are two methods you can use to map LDAP groups:
• Based on LDAP user object information such as DN or any attribute.
(See Mapping based on LDAP user object information, following.)
• Based on a LDAP group object information. (See Using Windows domain-based group mapping, on page 3-4.)
Note
See your LDAP administrator for more specific information about your
site’s LDAP configuration.
Mapping based on LDAP user object information
To map based on LDAP user object information
1. In the LDAP and Windows Domain Based Grouping section of the
Group Management panel, select the Use LDAP User Object to Map Group option.
A new set of options appears.
3 - 6
2. In the LDAP Server box, enter the name of an LDAP server.
3. In the LDAP Port box, enter an LDAP port, such as 389.
Page 53
Setting Up FirePass Server Security
4. If you want to use SSL, select the Use SSL Connection option.
5. In the User DN box, enter a User DN. For example:
CN=Administrator,DC=demo,DC=FP,DC=com
6. In the User Password box, enter a password.
Note: You can leave the User DN and User Password text boxes
blank if your server allows anonymous access to perform a query.
7. In the Search Base DN box, enter a Search Base DN to specify
where DN searches start from. For example:
DC=demo,DC=FP works,DC=com
8. In the Filter Template box, enter a filter template to look up a user.
The filter template must be a valid LDAP query expression. Use%s
in the filter expression to insert a user name. For example, suppose
you enter the following filter template:
(&(objectclass=person)(cn=%s))
If the user name is george, the query when the user logs on is:
(&(objectclass=person)(cn=george))
9. Do one of the following:
• Select the Use Attribute to Map Group option if your LDAP
schema has an attribute that corresponds to a FirePass server
group.
• Select the Use Parent DN to Map Group option if the user’s
parent DN corresponds to a FirePass server group.
10. Click Update to display the appropriate mapping table next to the
Mapping option you just selected.
11. Do one of the following:
• If you selected the Use Attribute to Map Group option, and if
the attribute’s value corresponds verbatim to the name of a
FirePass server group, select the Map Query Result into Group
Name Verbatim option. Enter the LDAP attribute name in the
Attribute Name box.
• If you selected the Use Attribute to Map Group option, and the
attribute’s value does not correspond verbatim to the name of a
FirePass server group, enter an attribute name in the Attribute
Name box, and then enter an attribute value in the Attribute
Value box. From the Map to Group list, select the FirePass
server group that corresponds to the attribute value, and then
click the Add button. As necessary, continue mapping attribute
values to groups by entering attribute values, selecting the
FirePass server group from the list, and then clicking Add.
FirePass™ Server Administrator Guide3 - 7
Page 54
Chapter 3
For example, suppose you have an LDAP attribute named
Department that has three attribute values Financial department,
Sales department, and Marketing department. Suppose you also
have three FirePass server groups named Financial, Marketing,
and Sales.
In that example, you map these attributes to these groups as follows.
Choose this FirePass server group
Enter this attribute value
Financial departmentFinancial
Marketing departmentMarketing
Sales departmentSales
from the menu
• If you selected the Use Parent DN to Map Group option, enter a
DN value in the DN Value box. From the Map to Group list,
select the FirePass server group that corresponds to the DN value,
and then click the Add button. As necessary, continue mapping
DN values to groups by entering DN values, selecting the
FirePass server group from the menu, and then clicking Add.
For example, suppose you have these three container objects in
your LDAP schema to store users for each department:
In that example, you map these DN values to groups as follows.
Enter this DN value
ou=Financial,o=MyCompanyFinancial
ou=Marketing,o=MyCompanyMarketing
ou=Sales,o=MyCompanySales
Choose this FirePass server group
from the menu
12. In the text boxes in the LDAP Attributes to Obtain Personal
Information section, enter the LDAP attributes for first name, last
name, and email address.
3 - 8
Page 55
For example, here are some attributes that are used in a standard
LDAP schema.
Enter one of these attribute valuesIn this text box
Firstname, fn, nameAttribute for First Name
surname, snAttribute for Last Name
email, uid, mailtoAttribute for email
Mapping based on a LDAP group object information
To use this method, you should have a group object in your LDAP schema
that may be used to map FirePass groups. This object should have at least
two multi-valued attributes to specify users that belong to this group. The
first attribute specifies static members and is the list of user’s DNs. The
second attribute specifies dynamic members and is presented as a list of
LDAP URLs or LDAP queries that define the criteria of the group’s
membership.
Setting Up FirePass Server Security
To map based on LDAP group object information
1. In the LDAP and Windows Domain Based Grouping section of the
Group Management panel, select the Use LDAP Group Object to Map Group option.
A new set of options appears.
2. From the For the group drop-down list, choose the FirePass server
group that you want to map to.
3. Click the Add to List button to add the selected group to the
mapping list.
4. Click Edit next to the group you added to set up mapping
parameters for that group.
A new set of options appears.
5. In the LDAP Server box, enter the name of an LDAP server.
6. In the LDAP Port box, enter an LDAP port such as 389.
7. If you want to use SSL, select the Use SSL Connection option.
8. In the User DN box, enter a user DN. For example:
CN=Administrator,DC=demo,DC=FP works,DC=com
9. In the User Password box, enter a password.
Note: You can leave the User DN and User Password boxes blank if
your server allows anonymous access to perform a query.
FirePass™ Server Administrator Guide3 - 9
10. In the Search Base DN box, enter a Search Base DN to specify
where DN searches start from. For example:
DC=demo,DC=FP works,Dc=com
Page 56
Chapter 3
11. In the Filter for Group box, specify an LDAP query. It must be a
valid LDAP query expression. For example:
OU=Groups,O=MyCompany
12. In the Query Template for Static Members box, specify a query
template for static members. Use %logon% in the filter expression
to insert a user name. For example:
13. In the Attribute for Dynamic Members box, specify an attribute
for dynamic members.
14. In the Search Base DN for User box, specify a Search Base DN.
For example:
OU=People,O=MyCompany
15. Click the Update button to store the mapping parameters for the
selected group.
16. (Optional) To test the mapping parameters, enter a LDAP user name
in the Test Logon box, and then click the Test Mapping button.
3 - 10
Page 57
Working with user accounts
You can add user accounts to each group on the FirePass server by using
any of the following methods:
• Manually add users to each group. (See Manually adding user accounts,
following.)
• Import users into each group from a Windows Domain server. (See
Importing user accounts from a Windows domain server, on page 3-13.)
• Import users into each group from an LDAP server. (See Importing user accounts from an LDAP server, on page 3-15.)
• Import users into each group from a text file. (See Importing user accounts from a comma or tab delimited text file, on page 3-16.)
• Allow a signup template for each group to automatically adds users when
they log in for the first time, if the user has an existing account in a
RADIUS, LDAP, or Windows Domain server. (See Using signup templates to add user accounts, on page 3-16.)
All of these methods create user accounts in the FirePass server’s internal
database.
Setting Up FirePass Server Security
Manually adding user accounts
To manually add a user account
1. Under the Users tab on the left side of the Administrative Console,
click the User Management link.
The User Management screen opens.
FirePass™ Server Administrator Guide3 - 11
2. Click the New User button.
The User Details screen opens.
Page 58
Chapter 3
3. If you want to add the user to a group other than the default group,
choose the group from the Group drop-down list and then click the
Change Group button.
4. In the Logon text box, enter a user name for the user.
5. In the First Name, Last Name, and Middle Initial boxes, enter the
user’s first and last names, and middle initial.
6. In the Email box, enter the user’s email address.
7. Do one of the following:
• If the authentication for the selected group is handled by the
FirePass server’s internal database, enter the user’s password in
the Password and Validate text boxes.
• If the authentication is handled by an external VASCO server,
enter the user’s Token ID in the Token ID text box. (See Setting Up VASCO DigiPass authentication, on page 3-28.)
• If the authentication is handled by an external RADIUS, LDAP,
or Windows Domain server, skip this step. The passwords for
these three servers are stored in the external server instead of in
the FirePass server.
3 - 12
Page 59
Setting Up FirePass Server Security
8. (Optional) As necessary, select the options to force the user to
change their password on the initial logon, email the password to the
user, force periodic password changes, or deactivate the account
after a specified period of time.
9. To generate a key that enables the user to install the My Desktop
client software, select the Generate Installation Key option.
If you select this option, the FirePass server sends an email message
to the user that contains instructions for downloading and installin g
the My Desktop client software.
You can also generate the installation key at another time. (See
Generating a My Desktop client software installation key, on page
3-21.)
10. Select a User mode option for the user. A Manager can view the
FirePass server system statistics. A User can not view statistics.
11. To grant access permissions for the user, select the MyDesktop Access option and/or the MyNetwork Access option.
12. Click the Add User button.
13. If you chose the option to generate a key, click the Click to Pick Up the Key button in the next panel that appears.
The installation key for the user is listed in the Existing FirePass
server Installation Keys panel.
14. Do one of the following:
• Write down the installation key so you or the user can use it later
for installing the My Desktop client software. (See Installing My Desktop client software at a user’s computer, on page 3-22.)
• Email the key to the user by clicking the Send button.
Importing user accounts from a Windows domain server
To import user accounts from a Windows domain server
1. In the User Management panel, click the Windows Domain Import
button.
The Windows Domain Import screen opens.
2. If you want to add the users to a group other than the default group,
select the group from the For the group drop-down list.
3. In the Domain Name box, specify the name of the Windows
domain you want to import users from.
FirePass™ Server Administrator Guide3 - 13
4. (Optional) In the PDC Server Name box, specify the name of the
Primary Domain Controller (PDC) server if the domain or PDC is
on a different subnet than the FirePass server.
Page 60
Chapter 3
5. (Optional) In the WINS Server IP Address box, specify the IP
address of the WINS server if the domain or PDC is on a different
subnet than the FirePass server.
6. If the Windows domain PDC is not configured to accept anonymous
access to user and group information, select the Join Windows Domain option. Then specify the Domain Admin Name and
Domain Admin Password.
7. Click the Query Domain button.
The FirePass server performs a query in the Windows domain for all
users and user groups, and displays the results. If no results are
displayed, or you see an error message displayed, verify the domain
settings you specified.
8. To restrict the list to users from a particular domain group, choose
the group from the Domain Group Filtering dro p-down list and
then click the Filter Results button.
9. To store the user’s Domain as part of his FirePass server logon user
name, select the FirePass Logon Formatted as DOMAIN\Username option.
Note: This option is only necessary if there are FirePass server
users with identical user login names belonging to different
domains.
If you select this option during an import process, each imported
user must log in to the FirePass server using the format of
DOMAIN\username.
10. To automatically generate appropriate email addresses for users,
select an option from the Email Formatting drop-down list and
then click the Update Results button.
This step is necessary because email addresses are not available
when querying a Windows domain.
11. Select the users you want to add to the FirePass server. To select all
users in the list, click the Select All Users link at the bottom of the
panel.
12. As necessary, select the MyNetwork Access option and the
MyDesktop Access option to grant the users these access
privileges.
13. Select the Send Email to Users option if you want to notify new
users of their accounts.
14. Click the Add Users button to import the user accounts.
3 - 14
Page 61
Setting Up FirePass Server Security
Importing user accounts from an LDAP server
To import user accounts from an LDAP server
1. In the User Management panel, click the LDAP Import button.
The LDAP import screen opens.
2. If you want to add the users to a group other than the default group,
select the group from the Group list.
3. In the Host box, type the name or IP address of an LDAP server.
4. In the Port box, enter an LDAP port such as 389.
5. If you want to use SSL, select the Use SSL connection option.
6. In the User DN box, enter a user DN. For example:
CN=Administrator,CN=Users,DC=demo,DC=FP,DC=com
7. In the User Password box, enter a password.
Note: You can leave the User DN and User Password boxes blank if
your server allows anonymous access to perform a query.
8. In the Search Base DN box, enter a search base DN to specify
where DN searches start from. For example:
DC=demo,DC=FP,DC=com
9. In the Search Query box, enter a query that produces a draft user
list, which is basically the list of matching DNs.
The search query must be a valid LDAP query expression.
10. Click the Query button.
The LDAP import screen opens
11. Choose entries from the drop-down menus under the LDAP
Attribute heading to map the LDAP attributes into FirePass server
values, such as user name, first and last names, and email address.
Note that the first and last names can be extracted from a compound
attribute (such as cn). To avoid this, select the first empty item from
the Full Name drop-down list.
12. Click the Map Attributes button.
The query returns the list of matching users. Only the user records
that have attributes corresponding to user name have a check box in
front of them. The users with names already in the FirePass server
internal database do not have a check box.
13. Select the users you want to add to the FirePass server. To select all
users in the list, click the Select All Users link at the bottom of the
panel.
FirePass™ Server Administrator Guide3 - 15
14. As necessary, select the MyNetwork Access option and the
MyDesktop Access option to grant the users these access
privileges.
15. Select the Send Email to Users option if you want to notify new
users of their accounts.
Page 62
Chapter 3
16. Click the Add Users button to import the user accounts.
Importing user accounts from a comma or tab delimited text file
You can import user accounts from a text file that contains either commas or
tabs between each element of information, such as first name, last name, and
so on.
To import user accounts from a comma or tab delimited
text file
1. In the User Management panel, click the Import from File button.
The Import Users From Comma or Tab Separated List screen opens.
2. Enter or browse to the text file and then click the Load List button.
3. In the next panel, specify the order of the information fields in the
text file by choosing a field name from each drop-down menu.
4. Select one of the options to import all of the list, or a subset based
on logons or names, and then click the Process List button.
5. If you want to add the users to a group other than the default group,
choose the group from the Group drop-down list.
6. (Optional) If you selected an option to import a subset of users,
select the users you want to import by clicking the check box next to
their logon or name.
7. (Optional) As necessary, select the options to force the user to
change their password on the initial logon, email the password to the
user, force periodic password changes, or deactivate the account
after a specified period of time.
8. To grant access permissions for the user, select the MyDesktop Access option and/or the MyNetwork Access option.
9. Select an option to overwrite or skip users that already exist in the
FirePass server internal database.
10. Click the Import Users button or the Import Selected button.
Using signup templates to add user accounts
If some or all users at your site have an existing account in an external
RADIUS, LDAP, or Windows Domain server, you can use a signup
template to automatically add the users to the internal database when they
log in to the FirePass server for the first time. FirePass server displays a
dialog box where first-time users enter their user name, password, and other
information. The FirePass server retrieves the user’s login and account
information (except for password) from the external server and
automatically adds a user account to its internal database.
3 - 16
Page 63
Setting Up FirePass Server Security
If you are using an LDAP or Windows Domain server and you set up group
mapping, the FirePass server also retrieves the user’s group information and
adds the user to the corresponding mapped group in its internal database.
(See Using Windows domain-based group mapping, on page 3-4 and Using LDAP-based group mapping, on page 3-6.)
Note
The FirePass server adds users to the first group specified on the Signup
Template panel that matches the first group where it locates the user in an
external server. That is, if a user is a member of several groups in the
external server and you have mapped all of the groups to groups in the
internal database, the FirePass server adds the user to the first group on the
external server that matches the first group in the order specified on the
Signup Template panel. If necessary, you can move users to different groups
in the internal database if the groups are not mapped. (See Moving users to a different group, on page 3-4.)
To use a signup template
1. Under the Server tab, click the Signup templates link.
2. From the For the group drop-down list, select the group that you
want to use a signup template with.
The group must use RADIUS, LDAP, or Windows Domain
authentication.
3. Select the Allow Authenticated Signup by Template option.
4. Select a user mode option for the user.
•A Manager can view the FirePass server system statistics.
•A User cannot view statistics.
5. To grant access permissions for the user, select the MyNetwork Access option and/or the MyDesktop Access option.
6. To generate and email a key that enables the user to install the My
Desktop client software, select the Generate and email installation key option.
You can also generate the installation key later. (See Generating a My Desktop client software installation key, on page 3-21.)
7. Click the Update Template button.
Using NFS user permissions from a UNIX password file
FirePass™ Server Administrator Guide3 - 17
If you want to give FirePass server users the ability to access NFS file
servers using the FirePass server My NFS Webifyer (see Configuring the My NFS Webifyer, on page 4-6), you must assign NFS user permissions to
the users. You can either assign the permissions manually for each
individual user, or you can import a list of user’s NFS user permissions from
a UNIX password file. FirePass server stores each user’s User ID and Group
Page 64
Chapter 3
ID in the user’s existing FirePass server account. Note that each FirePass
server user’s logon name (user name) must be identical to the logon name in
the NFS servers. For example, a user with the logon name of tjones on the
FirePass server must also have tjones as the logon name on the NFS servers.
Note that this procedure does not create any new user accounts on the
FirePass server. It simply imports the NFS user permissions for existing
FirePass server users so that they can access NFS file servers.
Importing NFS user permissions from a UNIX password file
To import NFS User Permissions from a UNIX password
file
1. If you have not already done so, create the user accounts in the
FirePass server and make sure the logon name in the FirePass server
account is identical to the logon name in the UNIX password file.
2. Under the Users tab on the left side of the Administrative Console,
click the Import NFS users link.
The Import NFS Settings screen opens.
3. Copy the contents of a UNIX password file that contains the user
IDs and group IDs you want to import.
4. Paste the contents of a UNIX password file into the text box on the
Import NFS Settings panel.
5. Click the Import button.
The NFS user permissions are listed on the next panel next to each
FirePass server user’s logon name.
Note
User IDs below 100 are ignored because they are reserved for system
services.
Manually assigning NFS user permissions to a FirePass server user
You can manually assign NFS user permissions to a FirePass server user
when you first create the account, or at any time later.
To manually assign NFS user permissions to a FirePass
server user
1. Do either of the following:
• Create a new FirePass server user with a login name that is
identical to the logon name in the NFS servers. (See Manually adding user accounts, on page 3-11.)
3 - 18
• If the user account already exists, click the Edit button in the
User Management panel next to the user account you want to
assign NFS permissions to. Make sure the FirePass server login
name is identical to the logon name in the NFS servers.
Page 65
2. In the NFS Settings section at the bottom of the User's Details panel,
3. In the Group ID box, enter the NFS group ID.
4. Click the Add button.
Changing user accounts
To change a user account
1. In the User Management panel, click the Edit button next to the user
2. To change the user’s group membership, select a different group
3. Change the other user’s properties as necessary, and then click the
Setting Up FirePass Server Security
enter the NFS user ID in the User ID box.
account you want to change.
The User group screen opens.
from the Group list, and then click the Change group button.
Update user details button.
Activating, deactivating, or deleting user accounts
To activate, deactivate, or delete a user account
1. In the User Management panel, select one or more user accounts
that you want to activate, deactivate, or delete.
2. Do one of the following:
• To activate or deactivate the users, click the Activate/Deactivate
Selected button.
A lock icon is placed next to user accounts that are deactivated.
• Click the Delete Selected button, and then click the Delete button
to confirm the deletion.
Assigning administrative privileges to a user account
By default, the FirePass server includes a superuser account with the user
name of admin that has a complete set of administrative privileges. You can
also assign administrative privileges to an existing user account to allow the
user to be a FirePass server administrator.
To assign the administrative privileges, you must either be logged in as the
superuser, or logged in as a user who already has administrative privileges.
There is a range of administrative privileges that you can assign, such as
access to some or all of the tabs and panels in the Administration Console,
and to various groups of users. The activities of a user with administrative
privileges are logged in Application Logs.
FirePass™ Server Administrator Guide3 - 19
Page 66
Chapter 3
To assign administrative privileges to a user account
1. Log into the Administrative Console as the superuser, or as a user
who already has administrative privileges.
2. Under the Server tab on the left side of the Administrative Console,
click the Security link.
3. On the Security screen, click the Administrators link.
4. Enter the user’s login name in the text box and then click the Add
button.
The user’s name is added to the list in the FirePass Administrators
panel, but the user does not have administrative privileges until you
explicitly assign them.
5. To assign administrative privileges for features in the
Administration Console, click the Edit link in the Feature Access
column next to the user’s name.
The Feature Access screen opens.
Select these tab names to
allow the user access to
the tabs in the
Administrative Console.
Click these
Edit links to
allow access
to a subset of
the panels for
a particular
tab.
6. Do any of the following:
• To allow access to all tabs, panels, and features in the
Administrative Console, select the Allow Access to All Features
option, and then click the Save button.
• To allow access to a subset of the tabs in the Administrative
Console, select the tab names on the Feature Access panel, and
then click the Save button.
3 - 20
Page 67
Setting Up FirePass Server Security
• To allow access to a subset of panels associated with a tab, click
the Edit link next to the tab. For example, click the Edit link next
to the Server tab name to specify access to the panels associated
with the Server tab in the Administrative Console. Then, click the
Save button.
7. To assign administrative privileges for user groups, click the Edit
link in the Group Access column next to the user’s name in the
FirePass Administrators panel.
8. To allow access to all groups, select the Allow Access to All Group
option.
9. Click the Save button.
10. After you are finished assigning the administrative privilege, the
user can log into Administrative Console by using the URL,
https://server-name.company.com/, and then clicking Admin
Console in the left panel.
Or, the user can log into Administrative Console directly by using
the URL, https://server-name.company.com/stats/.
Searching for user accounts
You can limit the scope and the size of the list of users on the User
Management panel by searching for logon, name, email, or group.
To search for user accounts
1. In the User Management panel, choose Logon, Name, email, or
Group from the Search By drop-down list.
2. In the text box next to the Search By drop-down list, enter the
logon, name, email, or group you want to find.
3. Click the magnifying button next to the text box.
4. To display the entire list of users, click the Show All Records link.
Generating a My Desktop client software installation key
To install the My Desktop client software, each user needs a unique
installation key. If you did not select the option to generate the installation
key when you added a user, or if you need additional keys, you can generate
the installation key.
To generate a My Desktop installation key
FirePass™ Server Administrator Guide3 - 21
1. Under the Users tab, click the New Key link.
The Create New Installation Keys screen opens.
2. Enter your name, description of the user’s system, and the number
of keys.
Page 68
Chapter 3
3. Click the Generate Installation Keys button.
The FirePass server generates the keys and displays them on the
Existing FirePass Installation Keys panel, which displays the status
of generated keys.
4. To send the keys to users, enter each user’s email address in the
Send To box next to each key, and then click the Send button.
5. To drop a key so that you can generate a new one within your
license limits, click the Drop link next to the key.
Installing My Desktop client software at a user’s computer
You can install the My Desktop client software at a user’s computer on the
user’s behalf.
To install the My Desktop client software at a user’s
computer
1. If you are not at the user’s computer when you add the user’s
account, do not select the option to generate an installation key.
2. Using the user’s computer, log into the Administration Console.
3. Generate a new key by following the instructions in the previous
section, Generating a My Desktop client software installation key,
on page 3-21.
4. In the Existing FirePass Installation Keys panel, select the key, right
click, and then choose Copy from the context menu to copy the key
to the clipboard. Do not send the key to the user.
5. Under the Desktop tab, click the Download link.
6. In the panel that appears, click the Download Desktop Software
link.
7. Click Install from Current Location.
The download takes a few minutes (depending on the speed of the
computer). The installation program prompts you for an installation
(activation) key.
8. Right click in the installation program window, and then choose
Paste from the context menu to insert the key.
9. Enter the user name and password for the user.
3 - 22
Page 69
Setting Up FirePass Server Security
Setting up FirePass server authentication
Authentication is set up on a per group basis on the FirePass server. If you
are using the same authentication for all FirePass server users, you can
simply add all users to the FirePass server default group and use the same
authentication for the default group. But, if you want to use different
authentication for different users, you must create groups on the FirePass
server before setting up authentication. (See Working with groups, on page
3-2.)
You can either set up authentication using the FirePass server’s internal
database, or you can use an external server. The advantage of using an
external server is that you can use the same server to authenticate FirePass
server users as you use to authenticate network users.
You can set up FirePass server authentication using any combination of the
following methods for different groups:
◆
FirePass server’s internal database
This is the default authentication method. (See Converting to internal
database authentication, following.)
◆
RADIUS server
You can use a RADIUS server at your site that supports RSA’s SecurID
technology. Each user is issued a SecurID token. (See Setting up RADIUS server authentication, on page 3-24.)
◆
Windows domain server
You can use a Windows domain server for authentication. (See Setting
up Windows domain server authentication, on page 3-25.)
◆
LDAP server
You can use an LDAP server for authentication. (See Setting up LDAP
server authentication, on page 3-27.)
◆
VASCO DigiPass
This is a two-factor authentication that uses a combination of a dynamic
password and a digital signature to grant access to the FirePass server.
(See Setting Up VASCO DigiPass authentication, on page 3-28.)
If authentication is handled by the FirePass server, then strong hashes of
each user’s password is stored in the internal database. If the authentication
is handled by an external server, then each user’s password is stored in the
external server.
Converting to internal database authentication
FirePass™ Server Administrator Guide3 - 23
In most cases when you first set up the FirePass server, the default group
uses the internal database. If you then create new groups by copying settings
from the default group, the authentication for the new groups also uses the
internal database. In these cases, internal database authentication is already
Page 70
Chapter 3
set up and no other configuration is required. However, if you want to
convert a group’s authentication from an external server to the internal
database, use the following instructions.
To convert a group to internal database authentication
1. Under the Server tab, click the Authentication link.
The Authentication Scheme panel for the current authentication type
appears.
2. From the For the group drop-down list, select the group that you
want to set up authentication for.
3. Click the Internal User Database Authentication option link
toward the bottom of the panel.
Note
There is no other configuration required for internal database
authentication.
Setting up RADIUS server authentication
If the RADIUS authentication feature is licensed, the FirePass server can
authenticate using a RADIUS server. FirePass server fully supports RSA
extensions for RADIUS and is RSA-certified.
To set up RADIUS server authentication
1. Under the Server tab, click the Authentication link.
2. From the For the group drop-down list, select the group that you
want to set up authentication for.
3. Click the RADIUS authentication link from the list of options
toward the bottom of the panel.
4. In the Timeout box, enter the number of seconds before timing out
the authentication process.
Five seconds is recommended.
5. In the Retries box, enter the number of authentication retries.
Five retries is recommended.
6. In the Server box, enter the server’s name or IP address.
7. In the Port box, enter the server’s port.
By default, the port is 1645. If a different port is being used on the
RADIUS server, set the FirePass server to match.
3 - 24
8. In the Shared Secret box, enter the shared secret for the RADIUS
server.
9. (Optional) If you want to use a backup RADIUS server, select the
Use a Backup RADIUS Server option and enter the backup
server’s name or IP address, port number, and shared secret.
Page 71
Setting Up FirePass Server Security
10. Click the Save Settings button.
To test the RADIUS authentication settings
1. Click the Test button.
2. Enter a user name and password in the RADIUS server, and then
click the Test button.
Setting up a RADIUS server to work with the FirePass server
To use SecurID, make sure that the SecurID Radius service is running. The
FirePass server does not authenticate to the native SecurID protocol.
Even if the RADIUS service has been started from the SecurID options
window on an NT SecurID server, the service may not be active. In the
Windows Services Manager, make sure that the service is set to start each
time the server boots and is currently running. The RADIUS authentication
takes place on a different port than native SecurID authentication.
On the RADIUS server, the FirePass server needs to be set up as a client to
the RADIUS server. Then, a shared secret needs to be created and added to
both the RADIUS server and the FirePass server so the RADIUS server can
trust the FirePass server.
On all Secure ID servers, the SecurID server needs to be made a client of
itself to make the RADIUS server function. The RADIUS service functions
as a standalone process and if the SecurID server is not set up as a client of
itself, it rejects the authentication request and not store anything in the logs,
making this problem difficult at best to diagnose. The FirePass server
merely reports that the authentication has failed.
Note
The FirePass server uses the Radius protocol when communicating with the
RSA Radius or ACE server. If you are using a RSA ACE server, you must
add support for the Radius protocol in order for the FirePass server to
communicate with it. You can do this by adding a “Rad ius Agent Host” to
the RSA server configuration. For more information, see the documentation
for your RSA server.
Setting up Windows domain server authentication
If the Windows Domain authentication feature is licensed, you can use
Windows Domain authentication to authenticate users against an internal
Windows NT/2000/2003 based server. The following two authentication
modes are supported:
FirePass™ Server Administrator Guide3 - 25
◆
Native NTLM authentication
Native NTLM authentication is supported if you specify domain
administrative credentials when you set up Windows Domain
Page 72
Chapter 3
authentication on the FirePass server. This allows FirePass server to add
a machine account for itself, join the domain, and create a trust
relationship with the Primary Domain Controller (PDC). FirePass server
can then authenticate users using native NTLM services.
◆
Netlogon Share
If you do not specify domain administrative credentials when you set up
Windows Domain authentication on the FirePass server, then FirePass
server uses a more basic method for authenticating users. FirePass server
connects to the Primary Domain Controller netlogon share using the
authenticating user’s credentials to determine whether the user has a
valid account within the domain.
To set up Windows domain server authentication
1. Under the Server tab, click the Authentication link.
The Authentication Scheme screen opens.
2. From the For the group drop-down list, select the group that you
want to set up authentication for.
3. Click the Windows Domain Authentication link at the bottom of
the panel.
The Windows Domain Authentication Scheme screen opens.
4. In the Domain Name box, enter the name of the Windows domain.
5. (Optional) In the PDC Server Name box, specify the name of the
Primary Domain Controller (PDC) server if you want to use a
particular PDC when joining the Windows domain, or if the PDC is
on a different subnet than the FirePass server.
6. (Optional) In the WINS Server IP Address box, specify the IP
address of the WINS server to aid in name resolution of the
configured domain or PDC.
Note: The WINS server IP address is usually only necessary if the
domain and PDC are on a different subnet than the FirePass server.
7. If there are FirePass server users with identical user names
belonging to different Domains, select the FirePass Logon Formatted as DOMAIN\Username option to store the user’s
Domain as part of their FirePass server logon user name.
Note: This option is only necessary if there are FirePass server
users with identical user login names belonging to different
domains.
If you select this option, each user must log in to the FirePass server
using the format of DOMAIN\username.
8. If the FirePass server is able to retrieve Windows Domain groups
from the configured Domain, select a group from the User Must Belong to Domain Group drop-down list.
This option restricts authentication to users within that domain
group.
3 - 26
Page 73
9. If the FirePass server is to become part of the Windows domain and
perform native NTLM authentication services, click the Join Windows Domain option. Then specify the Domain Admin Name
and Domain Admin Password.
10. Click the Save Settings button.
To test the Windows Domain authentication settings
1. Click the Test Saved Settings button.
2. Enter a user name and password in the Windows domain, and then
click the Test Domain Authentication button.
Setting up LDAP server authentication
If the LDAP authentication feature is licensed, the FirePass server can
authenticate using any LDAP database, including a Windows Active
Directory.
Setting Up FirePass Server Security
To set up LDAP server authentication
1. Under the Server tab, click the Authentication link.
The Authentication Scheme screen opens.
2. From the For the group drop-down list, select the group that you
want to set up authentication for.
3. Click the LDAP Authentication link in the list of options.
4. In the Host box, enter the name or IP address of an LDAP server.
5. In the Port box, enter an LDAP port such as 389.
6. If you want to use SSL, select the Use SSL Connection option.
7. Do either of the following:
• Select the Lookup User's DN Using Template option. Then, in
the User DN Template box, enter a User DN template. Use
%logon% in the expression to insert a user name.
For example:
uid=%logon%,ou=People,o=acme
• Select the Lookup User's DN Using Query option. In the User
DN For Query box, enter a User DN query. In the Password
box, enter a password.
In the Search Base DN box, enter a Search Base DN to specify
where DN searches start from. For example:
ou=People,o=acme
FirePass™ Server Administrator Guide3 - 27
In the Search Query Template box, specify a search query
template. Use %logon% in the expression to insert a user name.
For example:
(&(uid=%logon%))
8. Click the Update button.
Page 74
Chapter 3
Setting Up VASCO DigiPass authentication
If the VASCO DigiPass authentication feature is licensed, the FirePass
server can authenticate using a VASCO server.
Each user is issued a security token that generates a unique and dynamically
time-limited password. The server has a similar algorithm associated with
the token’s serial number. When logging in, the user enters a static password
and a dynamic password generated by the token.
Typically, the FirePass server comes preconfigured with the VASCO token
keys. If necessary, you can import new tokens into the server from a
VASCO file.
To set up VASCO DigiPass authentication
1. Under the Server tab, click the Authentication link.
The Authentication Scheme screen opens.
2. From the Group drop-down list, choose the group that you want to
set up authentication for.
3. Click the VASCO DigiPass Authentication link at the bottom of
the panel.
The VASCO DigiPass Authentication Scheme screen opens. The
tokens are listed in the Tokens section.
4. (Optional) To import additional tokens from a VASCO file, click
the Browse button and select the file. Then, in the Encryption box,
enter the encryption key and click the Import button.
Note: To assign a token to a user, enter the token ID in the User
Details panel when you add or edit a user’s properties. (See
Manually adding user accounts, on page 3-11, or Changing user
accounts, on page 3-19.)
5. (Optional) To delete a token, select it in the Tokens section and
click the Delete Selected button.
3 - 28
Page 75
Setting up certificates
A valid server certificate is very important in establishing a transparent
HTTPS connection. The browser running on the user’s computer checks the
certificate against its built-in list of Certificate Authorities and verifies that it
has not expired and that the name in the certificate matches the FirePass
server’s DNS name. If there is an error or a mismatch, some browsers
display security warnings; other browsers, notably wireless ones, may refuse
a connection.
If the FirePass server is a pilot deployment, it comes with a preinstalled
server certificate that contains a server-name.FP.com URL. If not, the
FirePass server now comes pre-configured with a default SSL server digital
certificate of firepass.company.xyz, signed by a FirePass root Certificate
Authority. This certificate may be used for initial FirePass server
configuration, testing, and licensing, but must not be used in a production
FirePass server. You receive warning messages from your web browser
when using this default certificate, indicating that the certificate signing
authority is unknown and that the certificate name does not match that of
your server.
Setting Up FirePass Server Security
Generating a new certificate request
When you deploy the FirePass server into production, you must purchase
and install a digital certificate matching the FirePass server’s configured
host name. You can use the FirePass Administrative Console to generate a
request to a Certificate Authority for a valid certificate. (See Generating a server certificate request, on page 3-30.)
Installing a new certificate
You can change the FirePass server name to one that is appropriate for your
site, and then generate and install a new server certificate that uses the new
server name. It is important to keep your server certificate valid by renewing
it as necessary, usually every year. You can check the expiration date of the
server certificate on the Certificates panel. (See Installing or renewing a server certificate, on page 3-31.)
Using certificates to authenticate client computers
You can also install an optional client root certificate and optional certificate
revocation list (CRL), and configure the FirePass server to validate client
certificates installed at each user’s computer. You can use the client
certificates as part of a two-factor authentication system, or to limit access to
particular FirePass server Webifyers. (See Using client certificates to authenticate a user’s computer, on page 3-31.)
FirePass™ Server Administrator Guide3 - 29
Page 76
Chapter 3
Changing the FirePass server name
If you have a pilot FirePass server named server-name.FP.com (or some
other default name), and you want to generate and install a new server
certificate that is specific to your site, you must first change the server name.
To change the FirePass server name
1. Under the Server tab on the left side of the Administrative Console,
click the Maintenance link.
2. Click the Network Configuration link.
3. Click the Hosts link.
Enter the new fully-qualified domain name (FDQN). Be sure to
make a corresponding entry in your domain name server.
4. Generate and install a new server certificate, as below.
Generating a server certificate request
To obtain a server certificate, you must first generate a certificate request.
Then you must submit the request to a Certificate Authority.
To generate a server certificate request
1. Under the Server tab on the left side of the Administrative Console,
click the Maintenance link.
The Maintenance screen opens.
2. Click the Network Configuration link.
3. Click the Web Services link at the top of the screen.
4. Click the Configure link for the host name you intend to use.
5. On the configuration screen, check the Use SSL box.
6. Two new links now appear below this box: Edit certificates, and
Generate new certificate request. Click the Generate... link.
7. Enter the correct information in the certificate request.
All the information in the certificate request must be valid. If this is
your first certificate request, the issuer may require additional
information to verify your identity and validity of the data you have
submitted.
8. (Optional) If you want to generate a new private key, select the
Private Key option and enter an encryption password.
3 - 30
9. Click the Generate Certificate Request button.
10. On the following screen, click the Here link at the bottom of the
panel to download a Zip file that contains a certificate request.
Page 77
11. Unzip the zip file and send the certificate request file (called
newcert.csr) to a known Certificate Authority to be signed. When
asked by the Certificate authority, specify the type of the certificate
as mod_ssl.
Installing or renewing a server certificate
When you receive a new signed certificate from the Certificate Authority,
you must install the certificate and, if you requested one, the new private
key.
To install or renew a server certificate
1. Under the Server tab on the left side of the Administrative Console,
click the Maintenance link.
2. Navigate to Network Configuration/Web Services.
Click the Configure SSL Certificates link.
3. Select the certificate you want to renew and click the Edit link, or
click the Add New Certificate button.
Setting Up FirePass Server Security
4. Copy the new signed certificate to the clipboard and then paste into
the upper text box.
5. If you generated a new key, paste it into the middle text box, and
then enter the encryption password you specified when you
generated the certificate request.
6. If your certificate comes from a chained Certificate Authority, paste
the intermediate certificate chain in the lower text box.
7. Click the Go button.
Using client certificates to authenticate a user’s computer
The server certificate verifies the server’s identity to a user’s computer. You
also can require client certificates verifying the identity of a user’s computer
to the server, or limiting access to particular FirePass Webifyers. Client
certificates can be used as part of a two-factor authentication system, where
users must have a valid client certificate installed on their computer in
addition to knowing their user name and password. Alternatively, valid
client certificates can be used to restrict access to particular Webifyers. For
example, access to the FirePass server SSL VPN service can be limited to a
laptop computer equipped with a valid client certificate. The user then
would have access to the SSL VPN service from the laptop, but would not
have access from other locations such as public access kiosks.
FirePass™ Server Administrator Guide3 - 31
To use client certificates, you must have a server configured as a Certificate
Authority (CA) that can generate a client root certificate and the client
certificates based on the client root certificate. Or, you can purchase the
client root certificate and client certificates from an external CA.
Page 78
Chapter 3
Here is an overview of the steps for using client certificates to authenticate a
user’s computer:
◆
Install the client root certificate on the FirePass server. (See Installing a
client root certificate, following.)
◆
Enable the validation of client certificates. (See Enabling validation of
client certificates, on page 3-33.)
◆
Configure client certificate validation as part of the authentication for a
group. (See Configuring client certificate authentication, on page 3-33.)
◆
Instruct users how to download and install the client certificate on their
computer. (You can also email the client certificates to users.)
The FirePass server can then request and validate the computer’s client
certificate against its installed client root certificate as part of the
authentication process.
Whenever necessary, you can also install an optional certificate revocation
list (CRL) that contains a list of client certificates for users who you want to
deny access to the FirePass server. For example, you can exclude the client
certificates for users who have left your company. (See Installing a certificate revocation list, on page 3-34.)
Installing a client root certificate
To install a client root certificate on the FirePass server
1. Under the Server tab on the left side of the Administrative Console,
click the Security link.
1. Click the Certificates link.
The Certificates screen opens.
2. In the Configure SSL Client Certificate Validation section, click the
Install Cert link.
3. Do one of the following:
• Click the Browse button and select the client root certificate file.
• Copy the contents of the client root certificate and paste it into the
text box.
4. Click the Install Certificate button.
Note
You can only have one client root certificate installed at any one time. If a
root client certificate is already installed, it is overwritten when you install
the new one. You can also delete the existing root client certificate by
clicking the Delete Certificate button if you do not want any root certificate
installed.
3 - 32
Page 79
Enabling validation of client certificates
To enable validation of client certificates
1. After you have installed a client root certificate, select the Request
and Validate Client Certificate option on the Certificates panel to
enable validation of client certificates.
This option configures the FirePass server to request a client
certificate as part of the SSL session negotiation which occurs
before the client computer attempts to log in to the FirePass server.
The server also validates and logs the client’s certificate, but it does
not restrict access to the server. For information on restricting
access using client certificates, see Configuring client certificate authentication, following.
2. (Optional) To have the server automatically enter the user name on
the Login panel with the common name (CN) of the client
certificate, select the Auto-fill Login Username with Certificate Common Name option.
This is useful if the client certificate common name is the same as
the user’s login name. The user must still enter a valid password to
gain access to the FirePass server.
Setting Up FirePass Server Security
Configuring client certificate authentication
After installing the client root certificate and enabling the validation of
client certificates, you can configure client certificate validation as part of
the authentication for a group.
To configure client certificate authentication
1. Under the Server tab, click the Authentication link. From the For
the group drop-down list, select the group that you want to set up
authentication for.
2. In the Configure Client-Side SSL Certificate Validation section ,
choose one of the following options from the Client Certificate
drop-down menu:
• Not Required
This option disables client certificate authentication. The
FirePass server requests and logs a client certificate, but users
without client certificates are given access to the server.
• Required for User Login
This option enables client certificate authentication for user login
and requires a valid client certificate for two-factor authentication
of users. For example, you can configure a combination of
internal database authentication with client certificate validation .
To require that the user name on the Login panel must match the
common name (CN) of the client certificate, select the Login Username Must Match Certificate Common Name option.
FirePass™ Server Administrator Guide3 - 33
Page 80
Chapter 3
• Required for Access to Select Webifyers
This option enables client certificate authentication for access to
a set of Webifyers that you specify. Click the Webifyers Requiring Client Certificate for Access option and then select
the Webifyers you want to restrict access to. (You can also
restrict access to these Webifyers by choosing the Limit option in
the Client Certificate Validation section of each Webifyer
management panel.) To require that the user name on the Login
panel must match the common name (CN) of the client
certificate, select the Login Username Must Match Certificate Common Name option.
Installing a certificate revocation list
To install a certificate revocation list (CRL) on the FirePass
server
1. Under the Server tab on the left side of the Administrative Console,
click the Security link.
2. Click the Certificates link.
The Certificates screen opens.
3. In the Configure SSL Client Certificate Validation section, click
the Install CRL link.
4. Do one of the following:
• Click the Browse button and select the CRL file.
• Copy the contents of the CRL and paste it into the text box.
5. Click the Install CRL button.
3 - 34
Page 81
Setting Up FirePass Server Security
Limiting access to the administrative console by IP
address
To increase the security of the FirePass server, you can limit access to the
Administrative Console by source IP address and/or subnets. Your current
browser’s source IP address is always allowed in order to protect you from
accidentally locking the server.
To limit access to the Administrative Console by IP address
1. Under the Server tab on the left side of the Administrative Console,
click the Security link.
2. Click the Access by IP link.
The Limit IP Access screen opens.
3. In the Option 1 text box, enter the IP addresses or subnets you want
to allow access to. Separate addresses in the list with a blank space.
Use the format xxx.yyy.zzz.www for an explicit address, or
xxx.yyy.zzz.www/vv for an address/mask. You can also use this
alternative form for a subnet: xxx.yyy.zzz. For example:
192.168.2.1 192.168.2.3
192.168.2.1/16
192.168.2
What’s next?
4. Click the Go button next to the Option 1 text box.
5. If you want to allow unlimited access to all IP addresses again, click
the Go button next to the Option 2 text box.
Now that FirePass server security is set up, you are ready to use the
Administrative Console to finish the remaining configuration tasks:
• Configure the Webifyers that you want to make available to users. For
example, configure the SSL VPN Webifyer, if necessary. For more
information, see Chapter 4, Configuring the FirePass Webifyers.
• (Optional) If necessary, customize the appearance of the user’s home
panel, such as the logo and terms used for logging in. For more
information, see Customizing the user’s home page, on page 5-31.
FirePass™ Server Administrator Guide3 - 35
Page 82
Chapter 3
3 - 36
Page 83
4
Configuring the FirePass Webifyers
• Overview of the FirePass Webifyers
• Configuring the My Files Webifyer
• Configuring the My NFS Webifyer
• Configuring the My Intranet Webifyer
• Configuring the My E-mail Webifyer
• Configuring the Terminal Services Webifyer
• Configuring the AppTunnels Webifyer
• Configuring the Host Access Webifyer
• Configuring SSL-VPN
• Configuring the My Desktop Webifyer
• Configuring the X-Windows Access Webifyer
• Using client certificate validation for Webifyers
Page 84
Page 85
Overview of the FirePass Webifyers
The FirePass™ Webifyers™ provide remote users with web-based remote
access to a wide variety of network applications and resources, including
email servers, Intranet servers, file servers, terminal servers, and legacy
mainframe, AS/400, Telnet, and X-Windows applications. Each Webifyer
renders its respective resource into and out of Web browser formats. The
Webifyer’s particular tasks are dictated by the application being accessed
and the protocol being supported.
Webifyers are separately licensed. These Webifyers are available with
Release 4.0:
◆
My Files
Allows remote users to browse, upload, download, move, copy, or delete
files on shared directories. Supports SMB Shares, Windows
Workgroups, Windows NT 4.0 and Windows 2000 domains, and Novell
5.1/6.0 with Native File System pack. (See Configuring the My Files Webifyer, on page 4-3.)
◆
My NFS
Allows remote users to browse, upload, download, move, copy, or delete
files on UNIX NFS servers. (See Configuring the My NFS Webifyer, on
page 4-6.)
Configuring the FirePass Webifyers
◆
My Intranet
Allows remote users access to internal Web servers, including Outlook
Web Access email servers. (See Configuring the My Intranet Webifyer,
on page 4-8.)
◆
My E-mail
Allows remote users access to POP/IMAP/SMTP email servers and
LDAP address books using a Web browser. Users can send and receive
messages, download attachments, and attach files stored on the internal
LAN to send email messages. (See Configuring the My E-mail Webifyer,
on page 4-11.)
◆
Terminal Services
Provides remote users with Web-based access to Microsoft Terminal
®
Servers, Windows XP network-access-enabled desktops, Citrix
MetaFrame applications, and VNC servers. No additional enabling
software is required on the Terminal Servers or Windows XP computers
being accessed. (See Configuring the Terminal Services Webifyer, on
page 4-15.)
◆
AppTunnels
Provides access from client applications on remote user’s computers to
TCP/IP application servers. The AppTunnels Webifyer enables a
client-side application to communicate back to the corporate application
server using a secure tunnel between the user’s Web browser and the
FirePass server. (See Configuring the AppTunnels Webifyer, on page
4-18.)
FirePass™ Server Administrator Guide4 - 1
Page 86
Chapter 4
◆
Host Access
Provides remote users with Web-based access to legacy VT100, VT320,
Telnet, X-Term, and IBM 3270/5250 applications without any
modifications to the applications or application servers. (See Configuring the Host Access Webifyer, on page 4-21.)
◆
SSL VPN
Provides remote users with the functionality of a traditional IPSec VPN
client. Unlike an IPSec VPN client, the SSL VPN Webifyer does not
require any pre-installed software or configuration on the remote user’s
computer, and no server-side changes are required. (See Configuring SSL-VPN, on page 4-23.)
◆
My Desktop
Provides employees with full remote control access to their desktop
computers on the internal LAN. (See Configuring the My Desktop Webifyer, on page 4-31.)
◆
X-Windows Access
Provides remote users with access to X-Windows applications hosted on
UNIX and Linux servers.
Because you configure Webifyers separately for each group, you can allow
different types of access to different groups of users. For example, you can
allow one group of users to use SSL VPN, and prevent another group from
using it.
4 - 2
Page 87
Configuring the FirePass Webifyers
Configuring the My Files Webifyer
The My Files Webifyer allows remote users to browse and view files stored
on internal LAN file servers. As the FirePass administrator, you can
configure the My Files Webifyer to limit access for a particular group to the
file shares you specify. The FirePass server does not allow unrestricted
browsing, or browsing folders above the level of the share you specify.
Defining Network Folder Favorites for the My Files Webifyer
To define a network folder favorite for the My Files
Webifyer
1. Under the Webifyers tab, click the My Files link.
2. From the For the group drop-down list, select the group that you
want to configure the My Files Webifyer for.
3. In the Edit Network Folder Favorites section, click the Add New
link.
4. In the Name box that appears, specify a name for the file share that
you are defining as a My Files Favorite.
This name is displayed as a label for the My Files Favorite in each
user’s Web browser under the My Network Files icon. For example:
Company Literature.
Important: The Administration Console does not verify the path you
specify, so be sure to enter it correctly.
5. In the Path box, specify a path for the file share in Microsoft UNC
format. For example:
\\server-name\share_name
You can also use the variables %username% or %group% in the
path to insert the user’s login name or group in the path. For
example, you might define a path for a favorite to each user’s folder
that is named the same as the user’s login name. That is, the path
\\server-name\%username% links to \\server-name\john_doe
for the user with the login name of john_doe.
6. Click the Add New button.
Limiting a group’s access to the Network Folder Favorites
If you want to limit a group’s access to the Network Folder Favorites you
specified, select the Limit MyNetwork Access to Folder Favorites Only
option.
FirePass™ Server Administrator Guide4 - 3
Page 88
Chapter 4
Enabling virus scanning and file uploading for the My Files
Webifyer
By default, users can download files with the My Files Webifyer. You can
also choose to allow users in a group to upload files, and you can enable
virus scanning of all downloaded and uploaded files. If the FirePass server
detects a virus in the files, it terminates the download or upload process and
notes the termination in the session log.
Note
The FirePass server virus scanner is based on the open source virus
signatures. For information on the latest virus signatures, see
www.openantivirus.org.
To enable virus scanning for the My Files Webifyer
1. In the File Upload section of the My Files screen, select the Enable
Virus Scanner option.
To update the virus signatures for the My Files Webifyer
1. In the File Upload section of the My Files screen, click the Browse
button, select the VirusSignatures.credo file, and then click the
Upload button.
To enable file uploading for the My Files Webifyer
1. In the File Upload section of the My Files screen, select the Enable
File Upload option.
Configuring advanced settings for the My Files Webifyer
If the FirePass server contains two NICs, it is important to configure a
broadcast address for the internal NIC. If there is a WINS server on your
network, specify its address to facilitate name resolution of Windows
servers using the My Files Webifyer.
To configure advanced settings for the My Files Webifyer
1. In the Broadcast Address box in the Advanced My Network Files
Settings section, enter the broadcast address you want the FirePass
server to use for network broadcasts.
If the FirePass server contains one NIC, enter the server’s IP address
if the address is not already entered by default. If the FirePass server
contains two NICs, enter the IP address of the internal NIC (that is,
the NIC connected to the internal LAN).
4 - 4
2. In the WINS Address box, enter the IP address of the WINS server.
Page 89
Configuring the FirePass Webifyers
Important: The WINS Address setting is required for multi-segment
networks where the FirePass server and the LAN are on different
network segments, or when the LAN has multiple segments. If you
do not specify the IP address of the WINS server in a multi-segment
LAN environment, the My Files Webifyer does not work properly.
3. In the Default Domain/Workgroup box, enter the default domain
and workgroup for the FirePass server.
Important: The Default Domain/Workgroup setting is required for
deployments where the IP address of the FirePass server is not on
the target LAN.
4. To have the FirePass server attempt to automatically log into My
Files servers and shares using each user’s FirePass login user name
and password, select the Auto-login to My Network shares using FirePass user login credentials option.
Using client certification validation for the My Files Webifyer
You can restrict access to the My Files Webifyer to users in a group who
have a valid client certificate installed on their computer. For more
information, see Using client certificate validation for Webifyers, on page
4-38.
FirePass™ Server Administrator Guide4 - 5
Page 90
Chapter 4
Configuring the My NFS Webifyer
Like the My Files Webifyer, the My NFS Webifyer allows remote users to
browse and view files stored on internal UNIX NFS file servers. As the
FirePass administrator, you can configure the My NFS Webifyer to limit
access for a particular group to the NFS file shares you specify. The
FirePass server does not allow unrestricted browsing, or browsing
directories above the level of the specified server share.
Note
FirePass users cannot access NFS shares until they have been assigned a
UNIX-style User ID and Group ID. (See Using NFS user permissions from a UNIX password file, on page 3-17.)
Defining favorites for the My NFS Webifyer
To define a NFS favorite for the My NFS Webifyer
Under the Webifyers tab, click the My NFS link to open the My NFS
Webifyer screen.
4 - 6
1. From the For the group drop-down list, select the group that you
want to configure the My NFS Webifyer for.
2. In the NFS Favorites section, click the Add New link.
Page 91
Configuring the FirePass Webifyers
3. In the Name box, specify a name for the path that you are defining
as a My NFS Favorite.
This name is displayed as a label for the My NFS Favorite in the
user’s Web browser under the My NFS Files icon. For example:
Legal Documents.
4. In the Path box, specify a path for the NFS file share. For example:
server-name.company.com:/directory_name
Important: The Administration Console does not verify the path you
specify, so be sure to enter it correctly.
5. Click the Add New button.
Defining NFS shared folders for the My NFS Webifyer
You can specify NFS shared folders that you want to allow remote users to
browse with the My NFS Webifyer icon on the left side of the user’s Web
browser window. (The My NFS favorites are displayed on the right side of
the browser window.) The FirePass server queries the NFS server for any
exported file systems.
To define a NFS shared folder for the My NFS Webifyer
1. In the NFS Shared Folders section of the My NFS screen, click the
Add New link.
2. In the Name box, enter the name for the path that you are defining
as a My NFS shared folder. This name is displayed as a label for the
NFS shared folder in the user’s Web browser. For example: Public
3. In the Path box, specify a path for the NFS shared folder. For
example:
server-name.company.com:/directory_name/public
Important: The Administration Console does not verify the path you
specify, so be sure to enter it correctly.
4. Click the Add New button.
Limiting a group’s access to the NFS Favorites
If you want to limit a group’s access to the NFS Favorites you specified,
select the Limit NFS Access to Folder Favorites Only option.
Using client certification validation for the My NFS Webifyer
FirePass™ Server Administrator Guide4 - 7
You can restrict access to the My NFS Webifyer to users in a group who
have a valid client certificate installed on their computer. For more
information, see Using client certificate validation for Webifyers, on page
4-38.
Page 92
Chapter 4
Configuring the My Intranet Webifyer
The My Intranet Webifyer allows remote users to access Web servers on the
internal LAN in a unified and secure way. A user can either browse the
internal Web sites by the site’s name or internal IP address, or to use
Intranet Favorites that you define.
Defining intranet favorites for the My Intranet Webifyer
For each group, you can create a set of links to internal Web sites and URLs.
You can set any of these links or the Favorites screen as the default screen
that users see when displaying My Intranet for the first time during a
session. You can also specify whether you want a Web site to open inside
the existing browser window or in a separate window.
To define an Intranet favorite for the My Intranet Webifyer
Under the Webifyers tab, click the My Intranet link to open the My Intranet
Webifyer screen.
4 - 8
1. From the For the group drop-down list, select the group that you
want to configure the My Intranet Webifyer for.
2. In the Edit Intranet Favorites section, click the Add New link.
Page 93
Configuring the FirePass Webifyers
3. In the Name box, specify a name for the Intranet site that you are
defining as a My Intranet Favorite. This name is displayed as a label
for the My Intranet Favorite in each user’s Web browser under the
My Intranet icon. For example: Project XYZ Web Site
In the URL text box, specify the URL for an Intranet Web server.
For example:
http://server-name.company.com/index.html
4. (Optional) In the URL Variables box, specify variables to be either
appended or POSTed (see step 6) to the URL you specified in the
URL box. URL variables are useful in supporting automatic user
login to Intranet web sites or for customizing Intranet content for a
user. Specify the variables in the form:
where the %username% and %password% parameters can be
used within values. The %username% and %password%
parameters are replaced with the user's FirePass login user name and
password.
For example, suppose you specify this URL:
http://server.company.com
and these URL variables:
show_custom_content=1&user=%username%@company.com
For a FirePass user named johndoe, these variables would result in
an actual Favorite link of:
5. (Optional) If you want the URL variables you specified to be
POSTed instead of appended to the URL, select the Post URL Variables option.
POSTing the variables is a more secure way to use a user name and
password for logging into an Intranet site, because the variables are
POSTed to the site instead of being included as part of the URL. For
more information on URL variables, see the Online Help for the My
Intranet Webifyer screen.
6. (Optional) In the Enforce User-agent box, specify a User-Agent
string which the FirePass server presents to the internal Web server
instead of the actual browser's User-Agent.
This option is useful in situations where you need to simplify the
FirePass content if errors are occurring.
Note: For Exchange 2000 OWA, it is necessary to simplify the
content by specifying the following User-Agent string: Mozilla/4.7 [en] (Windows NT 4.0; U)
FirePass™ Server Administrator Guide4 - 9
Page 94
Chapter 4
The following table lists several other User-Agent strings.
BrowserUser-Agent String
IE 6.0Mozilla/4.0 (compatible; MSIE 6.0; Windows 98;
Q312461)
IE 5.5Mozilla/4.0 (compatible; MSIE 5.5; MSN 2.5; Windows
98)
IE 5.0Mozilla/4.0 (compatible; MSIE 5.0; Windows NT;
IE 4.5Mozilla/4.0 (compatible; MSIE 4.5; Windows NT)
IE 4.01Mozilla/4.0 (compatible; MSIE 4.01; Windows NT)
Netscape 4.5Mozilla/4.5 [en] (Win98; U)
Netscape 3.04Mozilla/3.04Gold (Win95; U)
Opera 5 Opera/5.12 (Windows 2000; U) [en]
Opera 5 mimicking
Netscape
CPT-IE401SP1; DigExt)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 98) Opera
5.01 [en]
Tip: An easy way to enter a user agent string is to copy and paste
the string from the Logons report. Click the Logons link under the
Reports tab, and copy the user agent string from the User Agent
column for various users in the group. Then paste the string into the
Enforce User-agent box in the My Intranet Webifyer screen.
7. To open the Intranet resource in a separate window on the user’s
screen, select the Open in New Window option.
8. Click the Add New button.
The Intranet Favorite is added to the Default drop-down list.
Limiting a group’s access to the Intranet Favorites
Using client certification validation for the My Intranet Webifyer
4 - 10
9. (Optional) To specify a default My Intranet Favorite that is accessed
automatically when users in the group open their My Intranet
Favorites, select a favorite from the Default drop-down list.
If you want to limit a group’s access to the Intranet Favorites you specified,
select the Limit MyNetwork Access to Intranet Favorites Only option.
You can restrict access to the My Intranet Webifyer to users in a group who
have a valid client certificate installed on their computer. See Using client certificate validation for Webifyers, on page 4-38.
Page 95
Configuring the FirePass Webifyers
Configuring the My E-mail Webifyer
The My E-mail Webifyer provides remote users with HTML access to
multiple POP and IMAP mailboxes, and LDAP address books. After
configuring a corporate email account, you can specify an LDAP server as a
source of email addresses instead of using the default list of FirePass users.
Configuring an email account
To configure an email account
Under the Webifyers tab, click the My E-mail link to open the My E-mail
Webifyer screen.
FirePass™ Server Administrator Guide4 - 11
1. From the For the group drop-down list, select the group that you
want to configure the My E-mail Webifyer for.
2. Select the Enable corporate mail account option.
3. In the Account name box, enter a name, such as Corporate Account, to identify the mail account.
4. In the Mail server box, enter the mail server’s host name or IP
address, such as f22.company.com.
Page 96
Chapter 4
5. From the Type drop-down list, select the mail server type (POP or
IMAP).
6. If you are using an IMAP mail server, enter a list of folders in the
IMAP Folders box that you want displayed. Enter a comma
between the folder names in the list.
This list prevents the confusion created by mail servers that display
items that are not email messages, such as contacts or calendars, as
empty email messages. Users can also add to the list themselves.
7. From the Login Information drop-down list, select one of the
following options:
• User supplies display and login information during first login
Select this option to obtain email information from each user
when they login for the first time.
• Use FirePass database for display and login information
Select this option to obtain each user’s email information from
the FirePass server’s internal database.
• Use LDAP query for mail server, display, and login
information
Select this option to obtain each user’s email information based
on an LDAP query. (See Obtaining email addresses from an LDAP server, on page 4-13.)
8. Click the Update button.
Obtaining each user’s email information based on an LDAP query
You can dynamically obtain the mail server na me, display name, and login
information for each user based on an LDAP query.
To obtain each user’s email information based on an LDAP
query
1. From the Login Information drop-down list on the My E-mail
Webifyer screen, select Use LDAP query for mail server, display, and login information.
A group of LDAP options appear.
2. In the LDAP server address box, enter the LDAP server name.
3. In the Port box, enter an LDAP port, such as 389.
4. If you want to use SSL, select the Use SSL Connection option.
5. In the Bind DN text box, enter the relative distinguished name to
bind to.
Note: You can leave this text box blank if you want to use the server
default.
4 - 12
6. In the Bind password box, enter a valid password.
Page 97
Configuring the FirePass Webifyers
Note: You can leave this text box blank if no authentication is
required.
7. In the Search Base box, enter the DN of the entry in the tree to be
used for the search. For example:
cn=Recipients,ou=Exchange,o=Acme, Inc.
8. In the Filter template box, enter a search filter. For example:
(&(uid=%s))
where %s is substituted by each user’s FirePass logon name.
9. In the Attribute for mail server box, enter the attribute in the
LDAP schema that contains the mail server name.
10. In the Attribute for user’s display name box, enter the attribute in
the LDAP schema that contains the user’s display name.
11. In the Attribute for user’s email address box, enter the attribute in
the LDAP schema that contains the user’s email address.
12. In the Attribute for user’s logon box, enter the attribute in the
LDAP schema that contains the user’s logon.
13. Click the Update button.
Disabling email attachment downloads
By default, email attachment downloads are enabled. If necessary, you can
disable attachment downloads.
To disable email attachment downloads
1. In the Message Settings section of the My E-mail Webifyer screen,
select the Disable attachment download option.
2. Click the Update button.
Obtaining email addresses from an LDAP server
By default, the My E-Mail Webifyer uses the FirePass internal database as a
source of email addresses. Alternatively, you can specify an LDAP server as
a source of email addresses.
To obtain email addresses from an LDAP server
1. In the Source for Address List section of the My E-mail Webifyer
screen, select the Use LDAP server to obtain addresses option
from the Address List drop-down list.
A group of LDAP options appear.
FirePass™ Server Administrator Guide4 - 13
2. In the LDAP Server box, enter the LDAP server’s name or IP
address.
Page 98
Chapter 4
3. In the Port box, enter an LDAP port, such as 389.
4. If you want to use SSL, select the Use SSL connection option.
5. In the Bind DN box, enter the relative distinguished name to bind
to.
Note: You can leave this box blank if you want to use the server
default.
6. In the Bind password box, enter a valid password.
Note: You can leave this box blank if no authentication is required.
7. In the Search Base box, enter the DN of the entry in the tree to be
used for the search. For example:
cn=Recipients,ou=Exchange,o=FirePass server
8. In the Filter template box, enter a search filter template. For
example:
(&(objectclass=person)(cn=*%s*))
where %s is substituted by user’s FirePass logon name.
9. In the Name Attribute box, specify the name attribute, which is
typically cn.
10. In the Address Attribute box, enter the email address attribute,
which is typically mail.
11. Click the Update button.
Using client certification validation for the My E-mail Webifyer
You can restrict access to the My E-mail Webifyer to users in a group who
have a valid client certificate installed on their computer. For more
information, see Using client certificate validation for Webifyers, on page
4-38.
4 - 14
Page 99
Configuring the FirePass Webifyers
Configuring the Terminal Services Webifyer
The Terminal Services Webifyer provides remote users with access to
internal LAN Microsoft Terminal servers, Windows XP desktop computers,
Citrix Metaframe servers, and VNC servers in a unified secure way. Users
have the option to either browse the servers by their name or internal IP
address, or to use favorites.
The Terminal Services Webifyer includes:
• Support for native Terminal Server-hosted applications
• Support for Citrix
• Automatic download and installation of the correct Terminal Services or
Citrix remote-platform client component, if it is needed but has not yet
been installed
For each user group, you can assign options and create a set of favorite links
to appropriate servers. You can also specify whether you want the terminal
services to open inside the existing browser window or in a separate
window.
®
MetaFrame applications
Configuring screen resolution and Terminal Services Favorites
Under the Webifyers tab, click the Terminal Services link to open the
Terminal Services Webifyer screen.
FirePass™ Server Administrator Guide4 - 15
Page 100
Chapter 4
To configure screen resolution and Terminal Services
Favorites
1. From the For the group drop-down list, select the group that you
want to configure the Terminal Services for.
2. To set the initial screen resolution for Terminal Servers and Citr ix
Metaframe for the current group, select a resolution from the
drop-down list in the Screen Resolution section. Users can also
overwrite this setting on an individual basis.
3. In the Edit Terminal Service Favorites section, click the Add New
link.
4. In the Name box, specify a name for the terminal service that you
are defining as a Terminal Service Favorite. This name is displayed
as a label for the Terminal Services Favorite in each user’s Web
browser under the My Terminal Services icon. For example: Citrix XYZ Application.
5. In the Host box, enter the host name or IP address of the server
running the terminal service.
Note: You can use a space separated list of IP addresses or host
names in the Host field for a Citrix Metaframe Server, a Citrix
Metaframe Browser, and VNC. The FirePass server attempts to use
the first entry in the list, and if that entry fails, the server proceeds
with other entries in the list until a working server is found.
6. From the drop-down list next to the Port box, select a server type.
After you select the server type, the appropriate default value for the
port is automatically entered in the Port text box. If necessary, you
can enter a different server port number.
Note: The Citrix Metaframe Browser type relies upon the Citrix
HTTPonTCP protocol, which must be enabled on the target server.
This type is useful in accessing Citrix server farms and resolving
application names to an IP address and port.
7. In the Select a Program box, enter the complete path and file name
of the program you want to run on the remote server, such as
c:\programs\notepad.exe.
8. In the Working Dir box, enter the directory where you want to run
the program. such as C:\temp.
9. To open the Terminal Service application in a separate window on
the user’s screen, select the Open in new window option.
10. To allow users access to the local drives on the remote server during
a terminal service session, select the Allow access to local drives
option.
11. Click the Add New button.
4 - 16
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.