HowToConfigureSSLVPNinCyberoam PDF
HowToConfigureSSLVPNinCyberoam PDF
Overview
SSL (Secure Socket Layer) VPN provides simple-to-use, secure access for remote users to the
corporate network from anywhere, anytime. It enables creation of point-to-point encrypted tunnels
between remote user and company‟s internal network, requiring combination of SSL certificates and a
username/password for authentication.
- Tunnel Access Mode: User gains access through a remote SSL VPN Client.
- Web Access Mode: Remote users can access SSL VPN using a web browser only, i.e.,
clientless access.
- Application Access Mode: users can access web applications as well as certain enterprise
applications through a web browser, i.e., clientless access.
Scenario
Configure SSL VPN in Cyberoam such that the remote user shown in the diagram below is able to
access the Web and Intranet Servers in the company‟s internal network. The user is to have Full
Access, i.e., Tunnel, Web and Application Access. The network particulars given below are used as
an example throughout this article.
Network Parameters
Note:
If the customer is using an external certificate authority, then upload the same from System
Certificate Certificate Authority.
Step 2: Create self-signed Certificate
Parameter Description
To set global parameters for tunnel access, go to VPN SSL Tunnel Access and configure
tunnel access settings with following values:
To create Bookmark, go to VPN SSL Bookmark and click Add. Create Bookmark using
following parameters.
Similarly, create a bookmark Intranet of type HTTP to allow access to the internal Intranet server.
Intranet is accessible in Web as well as Application Access Mode, while Telnet is accessible in
Application Access Mode.
Step 5: Configure SSL VPN Policy
To configure SSL VPN policy, go to VPN SSL Policy and click Add. Create policy using
parameters given below.
Parameter Description
Go to Identity Users User and select the user to which policy is to be applied. Here we have
applied it on user John Smith.
Under Policies section, select Full_Access for SSL VPN as shown below.
Click OK to update the user‟s SSL VPN Policy.
Use default port: 8443 unless customized. Access is available only to those users who have been
assigned an SSL VPN policy.
User is directed to the Main Page which displays Tunnel, Web or Application Access Mode section
according to policy applied on user.
For Tunnel Access, user needs to access internal resources through an SSL VPN Client.
- Download the SSL VPN client by clicking “Download Client” and follow the on-screen
instructions.
- Install the client on the remote user‟s system.
- On complete installation, the CrSSL Client icon appears in the system tray. Login to the Client
and access the company‟s internal network through SSL VPN.
For Web and Application Access, user can access internal resources using web browser, i.e.,
clientless access. In this, user needs to browse to https://<WAN IP address of Cyberoam:port> and
login.