Configure a remote access VPN policy

Use the Remote Access VPN Policy Wizard to quickly set up a basic remote access VPN policy. Enhance the configuration by adding optional attributes, then deploy the policy to your Firewall Threat Defense devices.

The wizard consists of five stages:

Stages of the remote access VPN wizard

Procedure


Step 1

Choose Secure Connections > Remote Access VPN and click Add.

In the Name field, enter the name for the remote access VPN policy.

Step 2

Select protocols and devices.

  1. In VPN Protocols, select SSL, IPSec-IKEv2, or both. These protocols establish secure connections over a public network through VPN tunnels.

  2. In Targeted Devices, select one or more devices as as your remote access VPN gateways.

Step 3

Configure connection profile.

In the Connection Profile Name field, enter the name for the VPN connection profile.

A connection profile includes settings and attributes for authentication, address assignments to VPN clients, and group policies. The default connection profile, DefaultWEBVPNGroup, is available when you configure a remote access VPN policy.

Step 4

Configure AAA settings.

Step 5

Configure client address pool.

You can assign client IP address pools for your remote users from a AAA server, a DHCP server, and local IP address pools. If you select multiple options, the order of the IP address assignment is AAA server, DHCP server, and local IP address pools.

  • Use AAA Server—Check this check box to assign client IP address pools from a AAA server. This option is supported only for realm and RADIUS authorization. Ensure that realm or RADIUS server is configured to provide client IP addresses.

  • Use DHCP Servers—Check this check box to assign client IP address pools from a DHCP server.

  • Use IPv4 DHCP Servers—Click the edit icon to add one or more DHCP servers.

  • Use IP Address Pools—Check this check box to assign client IP address pools from the Cloud-Delivered Firewall Management Center.

  • IPv4 Address Pools—Click the edit icon to add one or more IPv4 address pools.

  • IPv6 Address Pools—Click the edit icon to add one or more IPv6 address pools.

Step 6

Configure a group policy.

A group policy contains user-oriented attributes for remote access VPN connections. You can assign attributes to users or groups without configuring each attribute individually. The connection profile applies a group policy to define user access terms after the tunnel is established. When a user logs in, a group policy identified by the AAA server is applied. If no group policy has been identified for the user, the default group policy, DfltGrpPolicy is used. Click + to create group policies.

Step 7

Select the Secure Client image that the VPN users will use to connect to the remote access VPN.

When you deploy the remote access VPN policy on the Firewall Threat Defense device, and a client device initiates a VPN connection, the Secure Client package is automatically downloaded to the client device.

Click Add new Secure Client Image to add a new image, and select the required images.

Step 8

Configure VPN interfaces for the device and the identity certificate.

  1. Configure the device interfaces that users will use to connect to the VPN.

    From the Interface group/Security Zone drop-down list, choose a interface group or a security zone that contains device interfaces for the VPN connections.

    Check the Enable DTLS on member interfaces check box, if required.

    Note

    DTLS is applicable only for SSL protocol.

  2. Configure the identity certificate of the Firewall Threat Defense device.

    This certificate authenticates the VPN gateway to remote access clients.

    From the Certificate Enrollment drop-down list, choose a device certificate or click + to add a certificate.

Step 9

Configure access controls, including geolocation-based access control and access control for decrypted VPN traffic.

  1. Configure geolocation-based access control for your clients.

    With Version 7.7 or later, you can use a service access object on Firewall Threat Defense devices to control remote clients' VPN access based on geolocation before authentication. By default, there are no geolocation restrictions unless a service access object is specified. For more information, see Manage VPN Access of Remote Users Based on Geolocation and Configure a service access object.

  2. Configure access control for VPN traffic.

    By default, an access control policy inspects all decrypted VPN tunnel traffic. Check the Bypass Access Control policy for decrypted traffic (sysopt permit-VPN) check box to bypass this inspection. VPN filter ACLs and authorization ACLs from the AAA server still apply.

    Note

    If you select this option, you do not need to update the access control policy for remote access VPN.

  3. Verify the summary of the remote access VPN policy and click Finish to save the remote access VPN policy..

    The summary page shows all configured remote access VPN settings and provides links to required additional configurations before policy deployment.

    Click Back to make changes to the configuration, if required.

    You can view the policy in the Remote Access VPN page.


What to do next

Complete these configurations to ensure the policy to work on all devices.

After you deploy the remote access policy on the devices, use the Remote Access VPN dashboard (Insights & Reports > VPN dashboards > Remote Access VPN) to monitor real-time data from active remote access VPN sessions on the devices. You can quickly determine problems related to user sessions and mitigate the problems for your network and users.