Download User Guide - TheGreenBow
Transcript
Doc.Ref Doc.version Version VPN tgbvpn_ug_en 1.0 – Apr 2015 TheGreenBow VPN Certified 20.1.22 Does VPN Client Software support two-way authentication keys and Tokens? Yes. TheGreenBow supports several two-factor and two-way authentication Tokens to store users, personal credentials, such as private keys, passwords and digital certificates. Please see the Certified Token List. 20.1.23 How to connect to a remote Windows Domain by using the 'Enable before Windows logon' feature? To make it work, please proceed through the following steps: - Go to 'Phase 2' > 'Advanced' tab, select 'Enable before Windows logon'. Then click 'Save'. - Next time, you are on the logon windows, a tiny windows will appear and will allow you to open this VPN tunnel. Several VPN Connections can be established before Windows logon. - More info the User Guide, click on 'Search' on top left > and search for 'Gina'. 20.1.24 How to setup VPN connections and VPN ports for users in hotels or hotspots? For more information on the negotiation of NAT Traversal in IKE see IETF RFC 3948 (UDP Encapsulation of IPsec Packets), IETF RFC 3947 (Negotiation of NAT-Traversal in the IKE) or draft "draft-ietf-ipsec-nat-t-ike-08". Also see the TCP and UDP ports list. Here are the negotiation Phases in VPN connection and their default VPN Ports when TheGreenBow VPN Client software is behind any router: Phase Default Port Where to modify the ports? Phase1 negotiation UDP Port 500 Go to 'Config Panel' > 'Parameters' > 'IKE Port' Phase2 negotiation UDP Port 4500 Go to 'Config Panel' > 'Parameters' > 'NAT-T Port' Traffic after IPSec/IKE negotiation Stays on last port defined In some hotels, hotspots or airports, the UDP port 500 and 4500 for outgoing traffic might be prohibited, preventing any outgoing VPN Connections to your corporate network. So it is necessary to configure IKE and NAT-T ports accordingly. Here is an example of alternative VPN Port in Configuration Panel (i.e. remember this only affects UDP protocol): IKE Port NAT-T Port 80 443 If you decide to use non default VPN Ports (i.e. UDP 500 & UDP 4500), the destination router (i.e. at the edge of your corporate network) must be configured to reroute the incoming traffic associated with the new selected VPN ports onto the default UDP 500 & UDP 4500 so that they properly routed to the IPSec service. Here is the diagram for example above, knowing that some router models do not provide the capability to reroute ports within itself and two routers might be needed: TheGreenBow VPN Certified User Guide Property of TheGreenBow © 2015 66/80