SonicWALL Global VPN Quick start guide

  • Hello! I am an AI chatbot trained to assist you with the SonicWALL Global VPN Quick start guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
SonicWall™GlobalVPNClient
4.10
AdministrationGuide
Copyright©2017SonicWallInc.Allrightsreserved.
SonicWallisatrademarkorregisteredtrademarkofSonicWallInc.and/oritsaffiliatesintheU.S.A.an d/orothercountries.Allother
trademarksandregisteredtrademarksarepropert yoftheirrespectiveowners
Theinformationinthisdo cumentisprovidedinconnectionwithSonicWallInc.and/oritsaffiliates’products.Nolicense,expressor
implied,
byestoppelorotherwise,toanyintellectualproper tyrightisgrantedbythisdocumentorinconnectionwiththesaleofSonicWallproducts.
EXCEPTASSETFORTHINTH ETERMSANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,SONICWALLAND/OR
ITSAFFILIATESASSUMENOLIABILITYWHATSOE V ERAND
DISCLA IMSANYEXPRESS,IMPLIEDORSTATUTORYWARRANT YRELAT IN GTOITS
PRODUCTSINCLUD ING ,BUTNOTLIMIT EDTO,THEIMPLIEDWARRANT YOFMERCHANTABILITY,FITNESSFORAPAR TI CU L AR PURPOSE,OR
NON‐INFRINGEMENT.INNOEVENTSHALLSONICWALLAND/ORITSAFFILIATESBELIABLEFORANYDIRECT,INDIRECT,CONSEQUENTIAL,
PUNITIVE,SPECIALORINCIDENTALDAMAGES(INCLUDING,
WITHOUTLIMITAT I ON ,DAMAGESFORLOSSOFPROFITS,BUSINESS
INTERRUPTIONORLOSSOFINFORM ATION)ARISIN GOUTOFTHEUSEORINAB ILI TYTOUSETHISDOCUMENT,EVENIFSONICWALLAND/OR
ITSAFFILIATESHAVEBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.SonicWalland/oritsaffiliatesmakenorepresentationsor
warrantieswithrespectto
theaccuracyorcompletenessofthecontentsofthisdocumentandreservestherighttomakechangesto
specificationsandproductdescriptionsatanytimewithoutnotice.SonicWallInc.and/oritsaffili atesdonotmakeanycommitmentto
updatetheinfo rmationcontainedinthisdocument.
Formoreinformation,visithttps://www.sonicwall.com/legal/.
Global
VPNClientAdministrationGuide
Updated‐March2017
SoftwareVersion‐4.10
23200383000RevA
Legend
WARNING:AWARNINGiconindicatesapotentialforpropertydamage,personalinjury,ordeath.
CAUTION:ACAUTIONiconindicatespotentialdamagetohardwareorlossofdataifinstructionsarenotfollowed.
IMPORTANT,NOTE,TIP,MOBILE,orVIDEO:Aninformationiconindicatessupportinginformation.
SonicWallGlobalVPNClient4.10AdministrationGuide
Contents
1
3
IntroductiontoGlobalVPNClient......................................................6
GlobalVPNClientOverview ............... ................ ........
...................... 6
GlobalVPNClientFeatures ........................
.................................. 6
GlobalVPNClientEnterprise............
............................................. 8
AboutthisGuide..
.............................. ...................................... 8
TextConventions ..... .........................
............... ................ ..... 9
MessageIcons............
............... ................ ......................... 9
GettingStartedwithGlobalVPNClient .......................................
..........10
InstallingtheGlobalVPNClient....................................
.....................10
UsingtheSetupWizard ............... ..........
.............................. .....10
UpgradingGlobalVPNClientfromaPreviousVersion .......
............................... 14
CommandLineOptionsforInstallation..............
.............................. .......14
LaunchingtheGlobalVPNClient........
.............................. ..................15
SpecifyingGlobal
VPNClientLaunchOptions ...................... ................ ........ 16
ManagingtheGlobalVPNClientSystemTrayIcon ..... ................................ ....17
Adding
VPNConnections.................................. . ................ .........18
UnderstandingVPNConnections ....................................
............... .....18
CreatingaVPNConnectionUsingtheNewConnectionWizard.....................
.......... 19
ImportingaVPNConfigurationFile .................. .................
............... ....21
UsingGlobalVPNClientfromaDifferentWorkstation .......................
............... 21
WorkaroundForcedCreationofaNewLocallyCachedProfile .................. .......
.22
MakingVPNConnections ..............................................
..............24
Overview............ ................ ........
............... ................ ........24
AccessingRedundantVPNGateways .......
............... ................ ............... 24
EnablingaVPNConnection
............... ................ ............................. 25
EstablishingMultipleConnections ................ ................ ......
.................26
EnteringaPreSharedKey............................
.............................. .... 26
SelectingaCertificate.............
.................................................... 27
ProvidingUsernameandPasswordAuthentication..... ................ ................ .. ..28
Creatinga
ConnectionShortcut ........................................................ 28
ConnectionWarning........... ................ .............
.......................... 29
ConfiguringVPNConnectionProperties....... .............
............................30
DisplayingtheConnectionsPropertiesDialog..................
............... ............ 30
ConnectionPropertiesGeneralSettings.............. .....
............... ................ 31
ConnectionPropertiesUserAuthenticationSettings ..............
.......................... 32
ConnectionPropertiesPeersSettings.. ................ ..
................................ 33
PeerInformationDialog...............
............... ................ ............. 34
ConnectionPropertiesStatusSettings..
............................................. .....36
Contents
SonicWallGlobalVPNClient4.10AdministrationGuide
Contents
4
ManagingVPNConnections .............. . . . .............. . . ................ .........38
AboutVPNConnections.. ................ ....................
......................... 38
ArrangingConnections.......................
......................................... 38
RenamingaConnection......
......................................................... 38
DeletingaConnection............... .. ................ .......
............... .......... 39
SelectingAllConnections............... .......
........................................39
CheckingtheStatusofVPNConnections ....
............................................. 39
DisablingaVPNConnection .
............... ................ ............................ 40
UsingCertificates................. . .............. . . ......
...........................41
ObtainingCertificateInformation.................. ...
.............................. ....41
ManagingCertificates ............. .
.............................. .....................41
TroubleshootingtheGlobalVPNClient ........................ ............... . ....
.....43
ToolsforTroubleshooting . ................ ................ ..........
............... ....43
UnderstandingtheGlobal VPNClientLog .... .....................
........................ 43
OpeningtheLogViewerWindow.....................
............... ................ 44
SavingtheCurrentLog...... .........
............... ................ ............... 44
ManagingLogMessages.
............................................. ............. 45
ConfiguringtheLog ............................... .. .......
........................... 46
ConfiguringAutoLogging...... ..............
.............................. ........ 46
GeneratingaHelpReport ........
.............................. ........................ 47
AccessingSonicWallGlobalVPNClientTechnicalSupport................... ................ 48
ViewingHelpTopics.
.............................. ....................................49
UninstallingtheGlobalVPNClient .............................
.......................... 49
ConfiguringSonicWallAppliancesforGlobalVPNClients.................
.................50
AboutGroupVPNPolicies.............. ................ .
............... ................ 50
GlobalVPNClientLicenses ...............
............... ................ ............... 50
GroupVPNConnectionsSupported
byPlatform........................................... 50
ActivatingYourGlobalVPN Client
............... ................ ........................ 51
DownloadingGlobalVPNClientSoftwareandDocumentation............... ................ 51
Usingthedefault.rcfFile...
..........................................................52
Aboutthedefault.rcfFile...................... ................ ..
...................... 52
HowGlobalVPNClientUsesdefault.rcf......................
............................. 52
Deployingthedefault.rcfFile .................
.............................. ............ 53
Includingthedefault.rcfFilewiththeMSIInstaller
... ................ ................ ..53
Addingthedefault.rcfFiletotheInstallationDirectory .....
............................. 54
ReplacinganExisting.rcfFilewiththedefault.rcfFile . ...........
....................... 54
Creatingthedefault.rcfFile.......................
.............................. .......55
default.rcfFileTagDescriptions.........
............................................ 55
Sampledefault.rcfFile...
.............................. ............................... 57
Troubleshootingthedefault.rcfFile...................................
............... ....59
SonicWallGlobalVPNClient4.10AdministrationGuide
Contents
5
UsingtheGlobalVPNClientCLI.......................................................60
AbouttheGlobalVPNClientCLI...................................
..................... 60
CommandLineOptions..........................
.............................. ........ 60
CommandLineExamples.........
.............................. .......................60
LogViewerMessages............................. . ..............
...................62
ErrorMessages.......... ................ ....
........................................ 62
InfoMessages..... ...
............... ................ ................................ 67
WarningMessages................ ................ .. ..
.............................. ..71
SonicWallEndUserProductAgreement.............
...................................72
SonicWallSupport ..............
....................................................78
SonicWallGlobalVPNClient4.10AdministrationGuide
IntroductiontoGlobalVPNClient
1
6
IntroductiontoGlobalVPNClient
GlobalVPNClientOverviewonpage6
GlobalVPNClientFeaturesonpage6
GlobalVPNClientEnterpriseonpage8
AboutthisGuideonpage8
TextConventionsonpage9
MessageIconsonpage9
GlobalVPNClientOverview
TheSonicWall™GlobalVPNClientcreatesaVirtualPrivateNetwork(VPN)connectionbetweenyourcomputer
andthecorporatenetworktomaintaintheconfidentialityofprivatedata.TheGlobalVPNClientprovidesan
easytousesolutionforsecure,encryptedaccessthroughtheInternetforremoteusers.
CustomdevelopedbySonicWall,the
GlobalVPNClientcombineswithGroupVPNonSonicWallInternetSecurity
AppliancestodramaticallystreamlineVPNdeploymentandmanagement.UsingSonicWall’sClientPolicy
Provisioningtechnology,theSonicOSadministratorestablishestheVPNconnectionspoliciesfortheGlobalVPN
Clients.TheVPNconfigurationdataistransparentlydownloadedfromtheSonicWallVPNGateway(SonicWall
InternetSecurityAppliance)toGlobalVPNClients,removingtheburdenofprovisioningVPNconnectionsfrom
theuser.
ForconfiguringyourSonicWallsecurityappliancetosupportGlobalVPNClientsusingSonicOSGroupVPN,see
theSonicOSAdministrationGuideforthefirmwareversionrunningonyourSonicWallsecurityappliance (your
VPNgatewayappliance).
Topics:
GlobalVPNClientFeaturesonpage6
GlobalVPNClientEnterpriseonpage8
GlobalVPNClientFeatures
TheSonicWallGlobalVPNClientdeliversarobustIPsecVPNsolutionwiththesefeatures:
•EasytoUse‐ProvidesaneasytofollowInstallationWizardtoquicklyinstalltheproduct,an
easytofollowConfigurationWizardwithpointandclickactivationofVPNconnections,andstreamlined
managementtoolstominimizesupportrequirements.
•Multiple
LanguageSupport‐TheGlobalVPNClientuserinterfacesupportsEnglish,SimplifiedChinese,
Japanese,Korean,andBrazilianPortuguese.TheUIautomaticallydisplaysintheWindowsdisplay
language.
SonicWallGlobalVPNClient4.10AdministrationGuide
IntroductiontoGlobalVPNClient
7
ClientPolicyProvisioning‐UsingonlytheIPaddressorFullyQualifiedDomainName(FQDN)ofthe
SonicWallVPNgateway ,theVPNconfigurationdataisautomaticallydownloadedfromtheSonicWall
VPNgatewayviaasecureIPsectunnel,removingtheburdenfromtheremoteuserofprovisioningVPN
connections.
•XAUTHAuthenticationwithRADIUS
‐Providesaddedsecuritywithuserauthenticationaftertheclient
hasbeenauthenticatedviaaRADIUSserver.
•VPNSessionReliability‐AllowsautomaticredirectincaseofaSonicWallVPNgatewayfailure.Ifa
SonicWallVPNgatewayisdownthentheGlobalVPNClientcangothroughanotherSonicWallVPN
gateway.
•MultipleSubnet
Support‐AllowsGlobalVPNClientconnectionstomorethanonesubnetinthe
configurationtoincreasenetworkingflexibility.
•ThirdPartyCertificateSupport‐SupportsVeriSign,Entrust,Microsoft,andNetscapeCertificate
Authorities(CAs)forenhanceduserauthentication.
TunnelAllSupport‐ProvidesenhancedsecuritybyblockingalltrafficnotdirectedtotheVPNtunnel
to
preventInternetattacksfromenteringthecorporatenetworkthroughaVPNconnection.
•DHCPoverVPNSupport‐AllowsIPaddressprovisioningacrossaVPNtunnelforthecorporatenetwork
whileallowingWANDHCPforInternetAccessfromtheISP.
•SecureVPNConfiguration‐CriticalGlobalVPNClientconfigurationinformationislockedfromthe
user
topreventtampering.
•AESand3DESEncryption‐Supports168bitkey3DES(DataEncryptionStandard)andAES(Advanced
EncryptionStandard)forincreasedsecurity.AESrequiresSonicOS2.0orhigherontheSonicWallVPN
gatewayappliance.
•GMSManagement‐AllowsGlobalVPNClientconnectionstobemanagedbySonicWall’sawardwinning
Global
ManagementSystem(GMS).
•MultiPlatformClientSupport‐Supports32bitand64bitversionsofWindows:Windows10,Windows
8,Windows8.1,andWindows7.
•NATTraversal‐EnablesGlobalVPNClientconnectionstobeinitiatedfrombehindany deviceperforming
NAT(NetworkAddressTranslation).TheSonicWallGlobalVPNClientencapsulatesIPsecVPN
trafficto
passthroughNATdevices,whicharewidelydeployedtoallowlocalnetworkstouseoneexternalIP
addressforanentirenetwork.
•AutomaticReconnectWhenErrorOccurs‐AllowstheGlobalVPNClienttokeepretryingaconnectionif
itencountersaproblemconnectingtoapeer.Thisfeatureallows
theGlobalVPNClienttoautomatically
makeaconnectiontoaSonicWallVPNgatewaythatistemporarilydisabled,withoutmanual
intervention.
•GhostInstallationforLargeScaleInstallations‐EnablestheGlobalVPNClient’s virtualadaptertogetits
defaultaddressafterinstallationandthencreateaghostimage.
•NTDomainLogonScript
Support‐AllowsGlobalVPNClientstoperformWindowsNTdomain
authenticationafterestablishingasecureIPsectunnel.TheSonicWallVPNgatewaypassesthelogon
scriptaspartoftheGlobalVPNClientconfiguration.ThisfeatureallowstheVPNusertohaveaccessto
mappednetworkdrivesandothernetworkservices.
•Dual
ProcessorSupport‐EnablestheGlobalVPNClienttooperateondualprocessorcomputers.
•GroupPolicyManagement‐GlobalVPNClientsaccesscanbecustomizedandrestrictedtos pec ific
subnetaccess(RequiresSonicOSEnhanced).
•HubandSpokeVPNAccess‐AllowsIPaddressingfromSonicWallVPNgateway’sDHCPServertoGlobal
VPNClientfor
configuringadifferentsubnetforallremoteGlobalVPNClientsthanthesubnetofthe
LAN.MakeshubandspokeVPNaccesssimpler.WhenaGlobalVPNClientsuccessfullyauthenticates
withthecentralsite,itreceivesavirtualIPaddressthatalsograntsitaccesstoothertrustedVPNsites.
SonicWallGlobalVPNClient4.10AdministrationGuide
IntroductiontoGlobalVPNClient
8
•DefaultVPNConnectionsFile‐EnablestheSonicOS administratortoconfigureanddistributethe
corporateVPNconnectionswiththeGlobalVPNClientsoftwaretostreamlineVPNclientdeployment.
•SingleVPNConnectiontoanySonicWallSecureWirelessApplianceforRoaming‐Allowsuserstousea
singleVPNconnectiontoaccessthenetworks
ofmultipleSonicWallSecureWirelessappliances.
•AutomaticConfigurationofRedundantGatewaysfromDNS‐WhenanIPsecgatewaydomainname
resolvestomultiple IPaddresses,theGlobalVPNClientusestheIPaddressesinthelistasfailover
gateways.
TunnelStateDisplayEnhancement‐TheGlobalVPNClientprovidesinformationaboutthestateof
VPN
tunnels.Inadditiontothestatesofenabled,disabled,andconnected,theGlobalVPNClientindicates
whentunnelsareauthenticating,provisioning,andconnecting.
TunnelStatusPopUpWindow‐TheGlobalVPNClientalertsuserswhentunnelsareconnectedor
disconnectedbydisplayingasmallpopupwindow.
•SmartCardand
USBTokenAuthentication‐TheGlobalVPNClientisintegratedwiththeMicrosoft
CryptographicApplicationProgram(MSCryptoAPIorMSCAPI),whichenablestheGlobal VPNClientto
supportuserauthenticationusingdigitalcertificatesonSmartcardsandUSBtokens.
•NATTRFC3947Support‐AllowsforautomaticdetectionofNATalongthe
pathbetweentwoIKEpeers
duringIKEPhase1negotiation.OndetectionofNATinmiddle,packetsareUDPencapsulatedusingport
4500.
•DNSRedirect‐DNSqueriestoDNSsuffixassociatedwithVirtualAdapterarenotsentonthephysical
adapter.
TunnelAllSupportEnhancement‐Providestheabilitytoroutecleartraffic
todirectlyconnected
networkinterfacesthatareconfiguredwiththeRouteAllpolicy,whichisgenerallyusedintheWLAN
zone.
•ProgramAutoStartonVPNConnection‐Automaticallylaunchesaprogram,withoptionalarguments,
whensuccessfulVPNconnectionsareestablished,asspecifiedintheConnectionPropertiesdialog.
GlobalVPNClientEnterprise
GlobalVPNClientEnterpriseprovidesthesamefunctionalityastheGlobalVPNClientwiththeaddedfeatureof
licensesharing.
AboutthisGuide
TheSonicWallGlobalVPNClientAdministrationGuideprovidescompletedocumentationoninstalling,
configuring,andmanaging theSonicWallGlobalVPNClient.ThisguidealsoprovidesinstructionsforSonicWall
GlobalVPNClientEnterprise.
ForconfiguringyourSonicWallsecurityappliancetosupportGlobalVPNClientsusingSonicOSGroupVPN,see
theSonicOSAdministrationGuidefor
thefirmwareversionrunningonyourSonicWallsecurityappliance(your
VPNgatewayappliance).
Topics:
TextConventionsonpage9
MessageIconsonpage9
SonicWallGlobalVPNClient4.10AdministrationGuide
IntroductiontoGlobalVPNClient
9
TextConventions
MessageIcons
Thesespecialmessagesrefertonoteworthyinformation,andincludeasymbolforquickidentification:
Convention Use
Bold HighlightsitemsyoucanselectontheGlobalVPNClientinterface
ortheSonicOSmanagementinterface.
MenuItem>MenuItem Indicatesamultiplestepmenuchoice.Forexample,“selectFile>
Openmeans“selectthe
Filemenu,andthenselecttheOpen
itemfromtheFilemenu.
Screen Text Indicatestextasyouwouldseeitonacomputerscreenorwould
enteronacommandline.Forexample,
myDevice> show
alerts
WARNING:Importantinformationthatwarnsaboutapotentialforpropertydamage,personalinjury,
ordeath
CAUTION:Importantinformationthatcautionsaboutfeaturesaffectingfirewallperformance,security
features,orcausingpotentialproblemswithyourSonicWallappliance.
TIP:UsefulinformationaboutsecurityfeaturesandconfigurationsonyourSonicWallappliance.
IMPORTANT:Importantinformationonafeaturethatrequirescalloutforspecialattention.
NOTE:Supportinginformationonafeature.
MOBILE:UsefulinformationaboutmobileappsforyourSonicWallappliance.
VIDEO:LinkstovideoscontainingfurtherinformationaboutafeatureonyourSonicWallappliance.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
2
10
GettingStartedwithGlobalVPNClient
InstallingtheGlobalVPNClientonpage10
UpgradingGlobalVPNClientfromaPreviousVersiononpage14
CommandLineOptionsforInstallationonpage14
LaunchingtheGlobalVPNClientonpage15
SpecifyingGlobalVPNClientLaunchOptionsonpage16
ManagingtheGlobalVPNClientSystem
TrayIcononpage17
Thissectionprovidesinformationaboutinstalling,upgrading,andlaunchingtheSonicWallGlobalVPNClient.
InstallingtheGlobalVPNClient
TheSonicWallGlobalVPNClientusesaneasy tousewizardtoguideyouthroughtheinstallationprocess.
TheSonicWallGlobalVPNClientoperateson32bitand64bitversionsofWindows10,Windows8.1,Windows
8,andWindows7clientoperatingsystems.
TheGlobalVPNClientissupportedon
allSonicWallsecurityappliancesrunningGen5(5.0andhigher)andGen6
(6.1andhigher)SonicOSfirmwareversions.
UsingtheSetupWizard
Thissectionexplainshowtoinstallthe SonicWallGlobalVPNClientprogramusingtheSetupWizard.
TousetheSetupWizard:
1Downloadtheselfextractinginstaller,GVCSetupXX.exe(whereXXiseither32for32bitWindows
platformsor64for64bitWindowsplatforms) ,fromMySonicWall.
NOTE:InstallingtheGlobalVPNClientrequiresAdministratorrights.
NOTE:ForinformationonthenumberofSonicWallGlobalVPNClientconnectionssupportedbyyour
SonicWallapplianceandGlobalVPNClientlicensingforyourappliance,seeGlobalVPNClientLicenseson
page50.
IMPORTANT:Removeanyinstalled3rdPartyVPNclientprogrambeforeinstallingthelatestSonicWall
GlobalVPNClient.
IfyouhaveSonicWallGlobalVPNClientinstalled,youmustuninstallitbeforeinstallingversion4.10.x.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
11
2DoubleclickGVCSetupXX.exe.TheSetupWizardlaunches.
3 ClickNexttocontinueinstallationoftheVPNClient.TheLicenseAgreementpagedisplays.
4 SelecttheIAgreeradiobutton.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
12
5 ClickNext.TheInstallationFolderSelectionpagedisplays.
6 Optionally,tospecify acustominstallationlocation,clickBrowse.
a Selectthelocation.
b ClickOK.
7 Optionally,clicktheDiskCostbuttontoseethediskspacerequirements.
8UnderInstallSonicWallGlobalVPNClientforyourself,orforanyonewhousesthiscomputer,select
either
EveryoneorJustme.
9 ClickNext.Thenextpageindicatesthattheinstallerisreadytobegininstallation.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
13
10 ClickNext.TheGlobalVPNClientisbeinginstalledpagedisplays,whichindicatesthe statusofthe
installation.
11 WaitwhiletheSonicWallGlobalVPNClientfilesareinstalledonyourcomputer.Whentheinstallationis
complete,theGlobalVPN Clienthasbeensuccessfullyinstalledpagedisplays.
12 ClickClosetoexitthe
wizard.Afterasuccessfulinstallation,whathappensnextdependsonwhetheryou
hadsavedconnections:
IfyousavedtheconnectionconfigurationsfromapreviousversionoftheSonicWallGlobalVPN
Clientwhenuninstallingit,theGlobalVPNClientlaunches,andyourdefaultconnectionprompts
youforlogincredentials.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
14
Ifnopreviousconnectionsexist,theNewConnectionWizardlaunchesautomatically.Thisonly
occursthefirsttimetheGlobalVPNClientstartsup.Formoreinformation,seeCreatingaVPN
ConnectionUsingtheNewConnectionWizardonpage19,
UpgradingGlobalVPNClientfromaPrevious
Version
Upgradesfrompreviousversionsarenotsupported.IfyouhaveSonicWallGlobalVPNClientversion4.9.22or
earlierinstalled,youmustuninstallthatversionandrebootyourPCbeforeinstallingversion4.10.x.The4.10.x
installerdoesnotallowupgradingfromearlierversions.
CommandLineOptionsforInstallation
ThereareseveralcommandlineoptionsavailableforSonicW allGlobalVPNClientinstallation.
Alloptionsarecaseinsensitiveandmustbeprecededbyaforwardslash(/):
•/QQuietmode.Anormal(nonsilent)installationoftheSonicWallGlobalVPNClientreceivesthe
necessaryinputfromtheuserinthe
formofresponsestodialogs.However,asilentinstallationdoesnot
prompttheuserforanyinput,butinstead,usesthedefaultsforeveryoption.Simplytypeinthe
followingwhereXXiseither32for32bitWindowsplatformsor64for64bitWindowsplatforms:
GVCSetupXX.exe /q
•/T
Specifyatemporaryworkingfolderinwhichtoplaceanytemporaryfilesgeneratedduringthe
installationprocess.TheToptionmustbefollowedbyacolon(:)andthefullpathtothefolderthatyou
wanttouse.Forexample,typeinthefollowing:
GVCSetupXX.exe /t:C:\TemporaryFiles
•/CPlaceallfiles
extracted(MSIInstallerfile)fromtheinstallpackageintothefolderspecifiedintheT
option.TheCoptionisonlyvalidwhenusedtogetherwiththeToption.Forexample,typeoneofthe
following:
GVCSetupXX.exe /c /t:C:\TemporaryFiles
GVCSetupXX.exe /T:C:\TemporaryFiles /c
TIP:YoucanconfiguretheGlobalVPNClienttolaunchautomaticallyeverytimeyoulog
ontoyourcomputer,ontheGeneraltabintheView>Optionspage.Formoreinformation,
seeSpecifyingGlobalVPNClientLaunchOptionsonpage16
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
15
LaunchingtheGlobalVPNClient
TolaunchtheSonicWallGlobalVPNClient:
1 SelectStart>Programs>GlobalVPNClient.
2Youcandoanyofthefollowing:
ToclosetheGlobalVPNClientdialog,buthaveyourestablishedVPNconnectionsremainactive,
clickX,pressAlt+F4,orchooseFile>Close.
AmessageappearsnotifyingyouthattheGlobalVPNClientprogram
andanyenabled
connectionsremainactiveafterthedialogisclosed.
Ifyoudon’twantthisnotificationmessagetodisplayeverytimeyouclosetheGlobalVPNClient
dialog:
a) SelecttheDon’tshowmethismessageagaincheckbox.
b) ClickOK.
ToopentheGlobalVPNClientdialog:
DoubleclicktheGlobal
VPNClienticoninthesystemtray.
Rightclicktheicon,andtheselectOpenGlobalVPNClient.
CAUTION:ExitingtheSonicWallGlobalVPNClientfromthesystemtrayiconmenudisablesanyactive
VPNconnections.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
16
SpecifyingGlobalVPNClientLaunchOptions
YoucanspecifyhowtheSonicWallGlobalVPNClientlaunchesandwhatnotificationwindowsappearusingthe
controlsintheGeneraltaboftheOptionsdialog.ChooseView>OptionstodisplaytheOptionsdialog.
TheGeneraltabincludesthefollowingsettingstocontrolthe launchoftheGlobalVPNClient:
•Start
thisprogramwhenIlogin‐LaunchestheSonicWall GlobalVPN Clientwhenyoulogintoyour
computer.
•WarnmebeforeenablingaconnectionthatwillblockmyInternettraffic.ActivatesaConnection
WarningmessagenotifyingyouthattheVPNconnectionwillblocklocalInternetandnetworktraffic.
Rememberthelast
windowstate(closedoropen)thenexttimetheprogramisstarted‐Allowsthe
GlobalVPNClienttorememberthelastwindowstate(openorclosed)thenexttimetheprogramis
started.Forexample,ausercanlaunchtheGlobalVPNClientfromthesystemtraywithoutopeninga
windowonthedesktop.
•Whenclosingtheconnectionswindow‐SpecifieshowtheGlobalVPNClientbehaveswhenthewindow
isclosed:
Minimizethewindow(restoreitfromthetaskbar)‐Minimizesthewindowtotaskbarand
restoresitfromthetaskbar.
•Hidethewindow(reopenitfromthetrayicon)‐The
defaultsettingthathidestheGlobalVPN
Clientwindowwhenyoucloseit.YoucanopentheGlobalVPNClientfromtheprogramiconin
thesystemtray.EnablingthissettingalsodisplaystheShowthenotificationwhenIhidethe
connectionswindowcheckbox.
•Showthe notificationwhenIhide
theconnectionswindowSelectingthischeckbox
activatestheSonicWallGlobalVPNClient HideNotificationwindowwheneveryouclose
TIP:Youcan:
ChangethedefaultlaunchsettingforSonicWallGlobalVPNClient;seeSpecifyingGlobal
VPNClientLaunchOptionsonpage16formoreinformation.
CreateashortcuttoautomaticallylaunchtheGlobalVPNClientdialogandmaketheVPN
connectionfromthedesktop,taskbar,orStartmenu.SeeGlobal
VPNClientLicenseson
page50formoreinformation.
LaunchtheGlobalVPNClientfromthecommandline,SeeUsingtheGlobalVPNClientCLI
onpage60formoreinformation.
SonicWallGlobalVPNClient4.10AdministrationGuide
GettingStartedwithGlobalVPNClient
17
theGlobalVPNClientwindowwhilethe programisstillrunning.Themessagetellsyou
thattheGlobalVPNClientprogramcontinuestorunafteryouclose(hide)thewindow.
ManagingtheGlobalVPNClientSystemTray
Icon
WhenyoulaunchtheGlobalVPNClientwindow,theprogramiconappearsinthesystemtrayonthetaskbar.
ThisiconprovidesprogramandVPNconnectionstatusindicatorsaswellasamenuforcommonSonicWall
GlobalVPNClientcommands.RightclickingontheGlobalVPNClienticoninthesystem
traydisplaysamenuof
optionsformanagingtheprogram.
•OpenGlobalVPNClient‐Openstheprogramwindow.
•Enable‐DisplaysamenuofVPNconnectionsthatcanbeenabled.
Disable‐DisplaysamenuofVPNconnectionsthatcanbedisabled.
•OpenLogViewer‐Opensthe LogViewertoviewinformationalanderrormessages.
SeeUnderstanding
theGlobalVPNClientLogonpage43formoreinformationontheLogViewer.
•OpenCertificateManager‐OpenstheCertificateManager.SeeManagingCertificatesonpage41for
moreinformationontheCertificateManager.
•Exit‐ExitstheGlobalVPNClientwindowanddisablesanyactiveVPNconnections.
Movingthe
mousepointerovertheGlobalVPNClienticoninthesystemtraydisplaysthenumberofenabled
VPNconnections.
TheGlobalVPNClienticoninthesystemtrayalsoactsasavisualindicatorofdatapassingbetweentheGlobal
VPNClientandtheSonicWallgateway.
SonicWallGlobalVPNClient4.10AdministrationGuide
AddingVPNConnections
3
18
AddingVPNConnections
UnderstandingVPNConnectionsonpage18
CreatingaVPNConnectionUsingtheNewConnectionWizardonpage19
ImportingaVPNConfigurationFileonpage21
UsingGlobalVPNClientfromaDifferentWorkstationonpage21
UnderstandingVPNConnections
TheGlobalVPNClientallowsmultipleconnectionstobeconfiguredatthesametime,whethertheyare
provisionedfrommultiplegatewaysorimportedfromoneormorefiles.Becauseconnectionsmaybe
provisionedfrommultiplegateways,eachconnectionexplicitlystatesallowedbehaviorinthepresenceofany
connectionpolicyconflicts.You
mayhaveVPNconnectionsthatdon’tallowotherVPNconnectionsorInternet
andnetworkconnectionswhile theVPNpolicyisenabled.
TheVPNconnectionpolicyincludesalltheparametersnecessarytoestablishsecureIPsectunnelstothe
gateway.AconnectionpolicyincludesPhase1andPhase2SecurityAssociations(SA)parameters:
Encryptionandauthenticationproposals
Phase1identitypayloadtype
Phase2proxyIDs(trafficselectors)
ClientPhase1credential
Allowedbehaviorofconnectioninpresenceofotheractiveconnections
Clientcachingbehavior
AddinganewVPNconnectioniseasybecause SonicWall’sClientPolicyProvisioningautomaticallyprovidesall
thenecessaryconfigurationinformation
tomakeasecureconnectiontothelocalorremotenetwork.The
burdenofconfiguringthe VPNconnectionparametersisremoved fromtheGlobalVPNClientuser.VPN
connectionscanbecreatedusingthreemethods:
DownloadtheVPNpolicyfromtheSonicWallVPNGatewaytotheGlobalVPNClientusing
theNew
ConnectionWizard.Thiswizardwalksyouthroughtheprocessoflocatingthesourceofyour
configurationinformationandautomaticallydownloadstheVPNconfigurationinformationoverasecure
IPsecVPNtunnel.
ImportaVPNpolicyfileintotheSonicWallGlobalVPNClient.TheVPNpolicyissenttoyou
asa.rcffile,
whichyouinstallusingtheImport Connectiondialog.
Installthedefault.rcffileaspartoftheGlobalVPNClientsoftwareinstallationoradditafter
installingtheGlobalVPNClient.IftheSonicWallVPNGatewayadministratorincludedthe
SonicWallGlobalVPNClient4.10AdministrationGuide
AddingVPNConnections
19
default.rcffileaspartoftheGlobalVPNClientsoftware,oneormorepreconfiguredVPN
connectionsareautomaticallycrea tedwhentheprogramisinstalled.
CreatingaVPNConnectionUsingtheNew
ConnectionWizard
ThefollowinginstructionsexplainhowtousetheNewConnectionWizardtoautomaticallydownloadaVPN
connectionpolicyfortheGlobalVPNClientfromalocalorremoteSonicWallVPNgateway.
TousetheNewConnectionWizard:
1 ChooseStart>Programs>GlobalVPNClient.ThefirsttimeyouopentheSonicWallGlobalVPNClient,
theNewConnectionWizardlaunchesautomatically.
2IftheNewConnectionWizarddoesnotdisplay,tolaunchit,clicktheNewConnection button.
NOTE:Creatingadefault.rcffileanddistributingitwiththeGlobalVPNClientsoftwareallows
theSonicWallVPNGatewayadministratortostreamlineVPNclientdeploymentandallowsusersto
quicklyestablishVPNconnections.Ifadefault.rcffileisincludedwiththedownloadedGlobal
VPNClientsoftware,theVPNpolicyconfiguredby
theSonicWallVPNGatewayadministratoris
usedtocreateaconnectionautomaticallywhentheclientsoftwareisinstalled.Formore
informationoncreatingthedefault.rcffile,seeUsingthedefault.rcfFileonpage52.
NOTE:TofacilitatetheautomaticprovisioningofGlobalVPNClients,configureyourSonicWall
appliancebeconfiguredwithGroupVPN.Forinstructionsonconfiguringyourappliancewith
GroupVPN,seetheSonicOSAdministrationGuide.
NOTE:ForinstructionsonimportingacertificateintotheGlobalVPNClient,seeUsingCertificates
onpage41.
SonicWallGlobalVPNClient4.10AdministrationGuide
AddingVPNConnections
20
3 ClickNext.TheNewConnectionpagedisplays.
4EntertheIPaddressorFQDNofthegatewayintheIPAddressorDomainNamefield.Theinformation
youtypeintheIPAddressorDomainNamefieldappearsintheConnectionNamefield.
5 Optionally,ifyouwantadifferentnameforyour
connection,typethenewnameforyourVPN
connectionintheConnectionNamefield.
6 ClickNext.TheCompletingtheNewConnectionWizardpagedisplays.
7 Optionally,selecteitherorboth:
•Createadesktopshortcutforthisconnectionifyouwanttocreateashortcuticononyour
desktopforthisVPNconnection.
•Enablethisconnectionwhentheprogramislaunchedifyouwanttoautomaticallyestablishthis
VPNconnectionwhenyoulaunchtheSonicWallGlobalVPNClient.
8 ClickFinish.ThenewVPNconnectionappearsintheGlobalVPNClientwindow.
/