Overview
Secure Sockets Layer (SSL) VPN is an emerging technology that provides Site-to-Site VPN capability. SSL VPN has some unique features when compared with other existing VPN technologies. Most noticeably, SSL VPN uses SSL protocol and its successor, Transport Layer Security (TLS), to provide a secure connection between remote users and internal network resources.
Applicable version: All
Scenario:
UTM Configuration:
We will have to create four VPN rules for establishing a VPN in either Interzone or custom rule.
1. LAN -VPN
2. VPN-LAN
3. UTM-VPN
4. VPN-UTM
Select services as per your requirement or you can select any services and click on OK
Configuring SSL VPN Server Settings
Before establishing SSL VPN connections you need to configure the SSL VPN server on Seqrite UTM. The client will send request to this server and the server will authenticate the client as per the authentication settings. After successful authentication, the connection for communication will be established.
1. Navigate to VPN > SSL > Server Settings. The following screen appears.
2. Select a Certificate Authority for SSL VPN and set it as default using the Set Default button. If there is no Certificate Authority, you can also create a certificate using the ADD(+) button.
3. By default the SSL VPN Server is disabled. Select the Enable option to enable the server.
4. The following points explain the fields on a page, configure as required:
5. After entering all the required information, click Apply.
6. Go to the Site-to-site option to configure the SSL Server and Client.
7. Click on Add(+) option to add the SSL server.
8. Select Local Network and Click on Add(+) to add the Remote network.
9. Enter Additional Commands if any and then Click on Apply.
10. Enable the current status of the server and download the package. We will require this package to upload it while configuring SSL Client.
11. To configure SSL client on another site (Site B), Go to Site-to-site option.
12. Click on Add(+) option to add the SSL Client.
Upload the SSL server package we have downloaded.
13. Now after the successful configuration of both SSL server and client, the status will be enabled automatically and SSL site-to-site VPN got connected and you are able to access all the local services of a remote network.
Verification Steps:
We have done verification by following two ways.
1. Remote Desktop: Open the remote desktop application and take the RDP of the remote site network. If you are able to take remote access then it indicates that RDP service is working properly via VPN.
2. CMD Prompt: Once VPN is successfully established, open the command prompt and ping the remote side local network. You will successfully ping response from the remote network.
Please contact Seqrite Technical Support for more assistance