Download User Guide - TheGreenBow

Transcript
Doc.Ref
Doc.version
Version VPN
tgbvpn_ug_en
1.0 – Apr 2015
TheGreenBow VPN Certified
20.1.22 Does VPN Client Software support two-way authentication keys and Tokens?
Yes. TheGreenBow supports several two-factor and two-way authentication Tokens to store users, personal
credentials, such as private keys, passwords and digital certificates. Please see the Certified Token List.
20.1.23 How to connect to a remote Windows Domain by using the 'Enable before
Windows logon' feature?
To make it work, please proceed through the following steps:
- Go to 'Phase 2' > 'Advanced' tab, select 'Enable before Windows logon'. Then click 'Save'.
- Next time, you are on the logon windows, a tiny windows will appear and will allow you to open this VPN
tunnel. Several VPN Connections can be established before Windows logon.
- More info the User Guide, click on 'Search' on top left > and search for 'Gina'.
20.1.24 How to setup VPN connections and VPN ports for users in hotels or hotspots?
For more information on the negotiation of NAT Traversal in IKE see IETF RFC 3948 (UDP Encapsulation of
IPsec Packets), IETF RFC 3947 (Negotiation of NAT-Traversal in the IKE) or draft "draft-ietf-ipsec-nat-t-ike-08".
Also see the TCP and UDP ports list.
Here are the negotiation Phases in VPN connection and their default VPN Ports when TheGreenBow VPN Client
software is behind any router:
Phase
Default Port
Where to modify the ports?
Phase1 negotiation
UDP Port 500
Go to 'Config Panel'
> 'Parameters'
> 'IKE Port'
Phase2 negotiation
UDP Port 4500
Go to 'Config Panel'
> 'Parameters'
> 'NAT-T Port'
Traffic after IPSec/IKE
negotiation
Stays on last port defined
In some hotels, hotspots or airports, the UDP port 500 and 4500 for outgoing traffic might be prohibited,
preventing any outgoing VPN Connections to your corporate network. So it is necessary to configure IKE and
NAT-T ports accordingly.
Here is an example of alternative VPN Port in Configuration Panel (i.e. remember this only affects UDP protocol):
IKE Port
NAT-T Port
80
443
If you decide to use non default VPN Ports (i.e. UDP 500 & UDP 4500), the destination router (i.e. at the edge of
your corporate network) must be configured to reroute the incoming traffic associated with the new selected VPN
ports onto the default UDP 500 & UDP 4500 so that they properly routed to the IPSec service. Here is the
diagram for example above, knowing that some router models do not provide the capability to reroute ports within
itself and two routers might be needed:
TheGreenBow VPN Certified User Guide
Property of TheGreenBow © 2015
66/80