Overview
Secure Sockets Layer (SSL) VPN is an emerging technology that provides remote-access VPN capability. SSL VPN has some unique features when compared with other existing VPN technologies. Most noticeably, SSL VPN uses SSL protocol and its successor, Transport Layer Security (TLS), to provide a secure connection between remote users and internal network resources.
Tunnelblick is use to established vpn connection from MAC OS system.
Tunnelblick is an open source graphic user interface for SSL VPN on Macintosh (Mac) OS X. It comes as a ready-to-use application with all necessary binaries and drivers. It does not require any additional installation. You just need to add the VPN tunnel configuration and encryption information. Tunnelblick Client can be used to establish SSL VPN connection between Mac OS and UTM.
Scenario
Prerequisite
This configuration consists of two (2) sections.
1. UTM Configuration
2. MAC OS X Configuration
1. UTM Configuration
We will have to create four VPN rules for establishing VPN in either inter-zone or custom rule.
A. LAN -VPN
B. VPN-LAN
C. UTM-VPN
D. VPN-UTM
Before establishing SSL VPN connections you need to configure the SSL VPN server on Seqrite UTM. The client will send request to this server and the server will authenticate the client as per the authentication settings. After a successful authentication the connection for communication will be established.
1. Navigate to VPN > SSL > Server Settings. The following screen appears.
2. Select a Certificate Authority for SSL VPN and set it as default using the Set Default button. If there is no Certificate Authority, you can also create a certificate using the ADD(+) button.
3. By default the SSL VPN Server is disabled. Select the Enable option to enable the server
4. The following points explains the fields on page, configure as required:
5. Select below Parameters as per your need.
6. After entering all the required information, click Apply .
Configuring Single PC remote access for SSL VPN
1. Navigate to VPN > SSL > Remote Access. The SSL VPN Remote access connections list is displayed. The current connections are displayed in the list.
2. Click the + (Add) icon. The Remote Access Add configuration page is displayed.
3. Enter the Connection Name.
4. Enter the Username and Password in the designated text boxes. Retype the Password in Confirm Password text box. These credentials are used for authentication.
5. Select “Local networks” that you want to configure for Remote Access from the networks that are listed.
6. Add “Additional Commands” if any.
7. Click Apply.
8. Once the user is created turn one “Status” and Click on “Download” option.
9. Select “Click here to download a zip containing only keys and configuration” and download the .tar file.
2. MAC OS X Configuration
Steps to configure VPN on MAC OS
5. Click on “I have configuration files”.
6. Create a new folder MAC on desktop and name it as VPNconfig (we can rename this folder later).
7. Copy this tar file to PC from previous (Section: Configuring Single PC remote access for SSL VPN, Step:-9)
8. Extract .tar file. This tar file contains Ca.sslcrt, Client.sslcrt, Client.sslkey and Client.sslovpn.
9. Drag and drop this .tblk to the TunnelBlick logo on the top left of the screen.
10. Rename folder - “VPNconfig”as “VPNconfig.tblk”(.tblk extension is to be given)
11. Drag and drop this .tblk file to the TunnelBlick logo on the top left of the screen.
12. Click on TunnelBlick to see the VPN successfully configured named as “VPNconfig”. Enter the credentials(Username and password) which we have created in above section ( Configuring Single PC remote access for SSL VPN, Step:-4)
13. UTM site status will automatically turn to Active state.
Please contact Seqrite Technical Support for more assistance.