SonicWALL Mobile Connect User guide

  • Hello! I am an AI chatbot trained to assist you with the SonicWALL Mobile Connect User guide. I’ve already reviewed the document and can help you find the information you need or explain it in simple terms. Just ask your questions, and providing more details will help me assist you more effectively!
SonicWall™MobileConnectfor
Windows10
UserGuide
Copyright©2017SonicWallInc.Allrightsreserved.
SonicWallisatrademarkorregisteredtrademar kofSonicWallInc.and/oritsaffiliatesintheU.S.A.and/orothercountries.Allother
trademarksandregisteredtrademarksarepropertyoftheirrespectiveow ners
Theinformationinthisdo cumentisprovidedinconnectionwithSonicWallInc.and/oritsaffiliates’products.Nolicense,expressor
implied,
byestoppelorotherwise,toanyintellectualproper tyrightisgrantedbythisdocumentorinconnectionwiththesaleofSonicWallproducts.
EXCEPTASSETFORTHINTHETERMSANDCONDITIONSASSPECIFIEDINTHELICENSEAGREEMENTFORTHISPRODUCT,SON ICWALLAND/OR
ITSAFFILIATESASSUMENOLIABILITYWHATSOEVERAND
DISCLA IMSANYEXPRESS,IMPLIEDORSTATU TORYWARRANT YRELATINGTOITS
PRODUCTSINCLUD ING ,BUTNOTLIMITEDTO,THEIMPLIEDWARR ANT YOFMERCHANTABILIT Y,FITNESSFORAPAR TI CU L A RPURP OSE,OR
NON‐INFRINGEMENT.INNOEVENTSHALLSONICWALLAND/ORITSAFFILIATESBELIABLEFORANYDIRECT,INDIRECT,CONSEQUENTIAL,
PUNITIVE,SPECIALORINCIDENTALDAMAGES(INCLUDING,
WITHOUTLIMITATION,DAMAGESFORLOSSOFPROFITS,BUSINESS
INTERRUPTIONORLOSSOFINFORMATION)ARISINGOU TOFTHEUSEORINABILITYTOUSETHISDOCUMENT,EVENIFSONICWALLAND/OR
ITSAFFILIATESHAVEBEENADVISEDOFTHEPOSSIBILITYOFSUCHDAMAGES.SonicWall and/oritsaffiliatesmakenorepresentationsor
warrantieswithrespectto
theaccuracyorcompletenessofthecontentsofthisdocumentandreservestherighttomakechangesto
specificationsandproductdescriptionsatanytimewithoutnotice.SonicWallInc.and/oritsaffiliatesdonotmakeanycommitmentto
updatetheinfo rmationcontainedinthisdocument.
Formoreinformation,visithttps://www.sonicwall.com/legal/.
Mobile
ConnectUserGuide
Updated‐March2017
SoftwareVersion‐1.0
23200382700RevA
Legend
WARNING:AWARNINGiconindicatesapotentialforpropertydamage,personalinjury,ordeath.
CAUTION:ACAUTIONiconindicatespotentialdamagetohardwareorlossofdataifinstructionsarenotfollowed.
IMPORTANT,NOTE,TIP,MOBILE,orVIDEO:Aninformationiconindicatessupportinginformation.
SonicWallMobileConnectforWindows10UserGuide
Contents
1
3
AboutMobileConnect.... . ..........................................................4
HowMobileConnectWorks ................................
............................. 4
SupportedPlatforms ...................
.......................................... ...... 4
Windows10
ProductSupport ................ .. ...................................... 5
UpgradingfromWindows8.1 ................... .. .................
............... ...5
SonicWallApplianceSupport............. ................
........................... 5
RequiredNetworkInformation......... ...........
................................... 6
InstallingMobileConnect............
.................................................7
ConfiguringVPN
Connections.........................................................9
CreatingaConnection.........................................
......................... 9
ConnectingtotheVPNServer....................
...................................... 11
ConfiguringConnectionswithPowerShell........
........................................ 12
CreatingVPNConnectionswithPowerShell.....
...................................... 13
ConfiguringVPNConnectionCustomXMLSettings......
...............................14
PowerShellExamplesforCustomizingVPNConnections .............
....................14
ConfiguringAdvancedVPNConnectionSettings. ........................
..................15
ConfiguringSMA1000Series/EClassSRAConnectionSettings...... ................
....15
ConfiguringSMA100Series/SRAandFirewallConnectionSettings.................. .....16
ConfiguringVPNConnectionTriggersinWindows10.....
.................................. 16
MonitoringVPNConnectionsinWindows...........
...................................18
DisplayingVPNConnectionNetworkInformation...........
............... ................ 18
DisplayingIPv4NetworkInformation...............
.................................. 18
DisplayingIPv6NetworkInformation............
..................................... 19
DisplayingRoutingInformation..........
............... ............................ 19
DisplayingDNSInformation....
............... ......................... ............20
MonitoringConnectionsintheWindowsTaskManager ................................... ..21
UsingtheVPNProperties
Window....................................................23
GeneralTab.......................................... .. ...
..........................23
OptionsTab.................. ....
....................................... ............24
SecurityTab.................................. .............
..........................25
NetworkingTab......................
................................................26
SharingTab
.......................................................................... 27
TroubleshootingVPNConnectionsinWindows10.... . . ...............
.............. . . . .28
SonicWallSupport ...............................
...................................29
Contents
SonicWallMobileConnectforWindows10UserGuide
AboutMobileConnect
1
4
AboutMobileConnect
SonicWall™Mobi leConnectforWindows10isanappthatisavailableintheWindowsStore.Theappincludesa
VPNpluginthatenablessecuremobileconnectionstoprivatenetworksprotectedbySonicWallsecurity
appliancesfordevices runningWindows10.
Topics:
HowMobileConnectWorksonpage4
SupportedPlatformsonpage4
HowMobileConnectWorks
Modernbusinesspracticesincreasinglyrequirethatusersbeabletoaccessanynetworkresource(files,internal
websites,etc.),anytime,anywhere.Atthesametime,ensuringthesecurityoftheseresourcesisaconstant
struggle.Whilemostusersareawarethattheymusttakecaretoprotectcomputersfromnetworksecurityrisks,
thissecurityawarenessdoesnotalwaysextendtomobiledevices.Andyet,mobiledevicesareincreasingly
subjecttosecurityattacks.Furthermore,mobiledevicesoftenuseinsecure,untrusted,publicWiFihotspotsto
connecttothe Internet.Itisthereforeachallengetoprovidesecure,mobileaccesswhilestillguardingagainst
theinherentsecurityrisksofusingmobile devices.
TheSonicWallMobileConnectforWindows10pluginprovidessecuremobileaccesstosensitivenetwork
resources.MobileConnectestablishesaSecureSocketLayerVirtualPrivateNetwork(SSLVPN)connectionto
privatenetworksthatareprotectedbySonicWallsecurityappliances.Alltrafficto
andfromtheprivatenetwork
issecurelytransmittedovertheSSLVPNtunnel.
TogetstartedwithMobileConnectforWindows10:
1EnsurethattheSonicWallSMAorfirewallappliancetobeusedbyMobileConnectisconnectedtothe
network.
2ConfiguretheVPNconnectionswithintheNetwork&Internet>VPNsectionoftheWindows10Settings
appwiththerequiredinformation(connectionnameandservername).
MobileConnectestablishesaSSL
VPNtunneltotheSonicWallsecurityappliance.
Youcannowaccessresourcesontheprivatenetwork.Alltraffictoandfromtheprivatenetworkis
securelytransmittedovertheSSLVPNtunnel.
SupportedPlatforms
ThefollowingsectionsdescribesupportedplatformsandnetworkrequirementsforSonicWallMobileConnect:
Windows10ProductSupportonpage5
UpgradingfromWindows8.1onpage5
SonicWallMobileConnectforWindows10UserGuide
AboutMobileConnect
5
SonicWallApplianceSupportonpage5
RequiredNetworkInformationonpage6
Windows10ProductSupport
SonicWallMobileConnectforWindows10issupportedondevicesrunningtheWindows10operatingsystem
fromMicrosoft.MicrosoftismakingWindows10availableasfreeupgradeforqualifiedWindows7,Windows
8.1,andWindowsPhone8.1devices.SeethefollowingURLformoreinformation:
http://www.microsoft.com/enus/windows/windows10faq
DownloadSonicWallMobile
ConnectforWindows10usingthefollowingURL:
http://microsoft.com/store/productid/9WZDNCRDSFKZ
UpgradingfromWindows8.1
VPNconnectionsconfiguredfortheMobileConnectinboxplugininWindows8.1willnotworkafterupgrading
toWindows10untiltheMobileConnectapphasbeendownloadedandinstalledfr omtheWindowsStore.The
VPNconnectionwillstillappearintheSettingsapp,however,clickingConnectwillshowthe
errorApplication
NotFound.
Inthiscase,the StoreappwillbeautomaticallylaunchedandtheMobileConnectapppagewillbedisplayed.
OnceMobileConnecthasbeensuccessfullyinstalled,clickingConnectontheVPNconnectionwillnowworkas
expected.
SonicWallApplianceSupport
SonicWallMobileConnectisafreeappavailablefordownloadfromtheWindowsStore,butrequiresa
concurrentuserlicenseononeofthefollowingSonicWallsolutionstofunctionproperly:
SonicWallfirewallappliancesincludingtheTZ,NSA,EClassNSA,andSuperMassive™9000Seriesrunning
SonicOS5.8.1.0orhigher
SonicWallMobileConnectforWindows10UserGuide
AboutMobileConnect
6
SonicWallSecureMobileAccess100Series/SRAappliancesrunning7.5orhigher
SonicWallSecureMobileAccess1000Series/EClassSRAapp liancesrunning10.7orhigher
RequiredNetworkInformation
TouseMobileConnect,youwillneedthefollowinginformationfromyournetworkadministratororITSupport:
•Servernameoraddress—ThisiseithertheIPaddressorURLoftheSSLVPNserverthatyouwillconnect
to.
Usernameandpassword—Typically,youwillberequiredtoenteryourusernameandpassword,
althoughsomeconnectionsmaynotrequirethis.
•DomainorLoginGroupname—ThedomainorlogingroupnameoftheSSLVPNserver.Mobi leConnect
maybeabletoautomaticallydeterminethiswhenitfirstcontactstheserver,ortheremaybemultiple
domainsthatcanbeselected.
DNSDomainSettingsonSonicWallAppliances
BeforeMobileConnectuserswillbeabletoaccesstheprivatenetwork,thenetworkadministratormust
configuretheDNSDomainontheSonicWallappliance.WhentheMobileConnectuseraccessesaURLonthe
privatenetwork,theconfiguredDNSdomainisusedtoresolvethehostnamelookup.Forpublicdomainsthat
donotmatchtheconfiguredDNSdomain,theDNSserverfortheWiFior3G/4Gnetworkisused.
ThefollowinginformationisforSonicWallnetworkadministrators:
TheDNSDomainconfigurationprocessvaries,dependingonthetypeofSonicWallappliancebeingused:
•SonicWallfirewallappliances—OntheSSLVPN>ClientSettings
page,entertheDNSdomainnamein
theDNSDomainfield.
•SonicWallSMA100Series/SRAappliances—TheDNSdomaincanbeconfiguredeitherglobally,atthe
grouplevel,orattheindividualuserlevel:
•Globallevel:OntheNetwork>DNSpage,entertheDNSdomainnameinthe
DNSDomainfield.
•Grouplevel:OntheUsers>LocalGroupspage,clicktheediticonforthegroup.Clickonthe
NetExtender/MobileConnecttabandentertheDNSdomaintheDNSDomainfield.
•Userlevel:OntheUsers>LocalUserspage,clicktheediticonfortheuser.
Clickonthe
NetExtender/MobileConnecttabandentertheDNSdomaintheDNSDomainfield.
•SonicWallSMA1000Series/EClassSRAappliances—TheDNSdomaincanbeconfiguredeitherglobally
orforspecificIPaddresspools:
•Globallevel:FromthemainnavigationmenuintheApplianceManagementConsole(AMC),click
NetworkSettings.IntheNameresolutionarea,clickEdit.TheConfigureNameResolutionpage
appears.EntertheDNSdomainnameintheSearchdomainsfield.
•IPaddresspoollevel:FromthemainnavigationmenuinAMC,clickServices.UnderAccess
services,intheNetworktunnelservicearea,click
Configure.TheConfigureNetworkTunnel
Servicepageappears.ClickthenameoftheIPaddresspoolyouwanttoedit.TheConfigureIP
AddressPoolpageappears.TotherightoftheAdvancedheading,clickthearrowicon.Selectthe
CustomizedefaultsettingscheckboxandentertheDNSdomain
nameintheSearchdomains
field.
NOTE:TheMobileConnectuserdoesnotneedtoperformanyconfigurationtasksrelatedtoDNS.
SonicWallMobileConnectforWindows10UserGuide
InstallingMobileConnect
2
7
InstallingMobileConnect
ThissectiondescribeshowtoinstallMobileConnect.SonicWallMobileConnectforWindows10isinstalled
fromtheWindowsStore.
ToinstallMobileConnect:
1OnyourWindows10device,launchthe Storeapp.
2Inthesearchfield,typeinSonicWallMobileConnectandclickEnter.
3Inthesearchresults,selectSonicWallMobileConnect.
SonicWallMobileConnectforWindows10UserGuide
InstallingMobileConnect
8
4 SelectInstall.Theappwillbegindownloadingandinstallonyourdevice.
5Wheninstallationiscomplete,theSonicWallMobileConnecticonwillappearinthelistofapplications
onyourWindows10device.
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
3
9
ConfiguringVPNConnections
ThissectiondescribeshowtoconfigureandinitiateaVPNconnectionusingSonicWallMobileConnectfor
Windows10.
Topics:
CreatingaConnectiononpage9
ConnectingtotheVPNServeronpage11
ConfiguringAdvancedVPNConnectionSettingsonpage15
ConfiguringVPNConnectionTriggersinWindows10onpage16
CreatingaConnection
InWindows10,VPNconnectionscanbecreatedintheSettingsapp.
TocreateaVPNconnection:
1 LaunchtheSettingsappandnavigatetoNetwork&Internet>VPN.
2UnderVPN,selectAddaVPNconnection.
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
10
3IntheAddaVPNconnectionwindow,selectSonicWallMobileConnectastheVPNprovider.
4Afterenteringalltherequiredinformation,clickSave.
OncetheVPNconnectionissuccessfullycreated,theVPNconnectionnameappearsinthelistof
connectionsandintheVPNsection.
IMPORTANT:Ifacustomportisrequired,thentheservernamemustbeenteredinURLformatinthe
Servernamefield,forexamplehttps://vpn.example.com:4433.
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
11
ConnectingtotheVPNServer
ToestablishaMobileConnectVPNsession:
1IntheActionCenter,selecttheVPNtoopentheSettingsappandconnecttheVPNbyselectingConnect.
2EnteryourusernameandpasswordwhenpromptedandtapOK.NotethattheWindowsSignInscreen
acceptstheSonicWallSMA100Series/SRAorFirewallappliancedomainorthe
SonicWallSMA1000
Series/EClassSRALoginGroupvalueastheMicrosoftdomainportionofthe username:
Username@Domain ORUsername@LoginGroup
Domain\UsernameORLoginGroup\Username
Example1:jdoe@SRADEMOorSRADEMO\jdoe,whereSRADEMOisthenameofthedomainforthe
SMA100Seri es/SRAappliance.
Example2:jdoe@CORPor
CORP\joe,whereCORPistheLoginGroupfortheSMA1000Series/EClass
SRAappliance.
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
12
Whentheconnectionissuccessfullyestablished,theStatuschangestoConnectedandtheDisconnect
buttonreplacestheConnectbutton.
Onceconnected,youcanaccesstheremotenetwork.TheNetworksscreenshowsthestatusoftheVPN
connection.
IftheVPNconnectionisinterrupted,theVPNiconshowsasdisconnectedandyou
willnolongerbeableto
accesstheremotenetwork.ReturntotheNetworksscreentoreestablish theVPNconnection.Windows10will
automaticallyattempttorees tablishinterruptedconnections.VPNconnectionsinWindows10alsocanbe
managedusingPowerShell.
ConfiguringConnectionswithPowerShell
Thissectionincludesthefollowingtopics:
CreatingVPNConnectionswithPowerShellonpage13
ConfiguringVPNConnectionCustomXMLSettingsonpage14
PowerShellExamplesforCustomizingVPNConnectionsonpage14
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
13
CreatingVPNConnectionswithPowerShell
TocreateaVPNconnection,usethePowerShellcommandAdd-VpnConnection(seehttp://
technet.microsoft.com/enus/library/jj55 4824.aspx).ThePluginApplicationIDfortheSonicWallMobileConnect
VPNpluginisSonicWALL.MobileConnect_e5kpm93dbe93j.Intheexamplebelow,aVPNconnectionto
vpn.example.comiscreatedwithdefaultoptions.ThisisequivalenttousingtheSettingsappontheWindows
10device.
ThefollowingisanexampleofthePowerShellcommandsforcreatingaconnection:
PS C:\> $xml = "<MobileConnect/>"
PS C:\> $sourceXml=New-Object System.Xml.XmlDocument
PS C:\> $sourceXml.LoadXml($xml)
PS C:\> Add-VpnConnection -NameVPN -ServerAddress vpn.example.com -
SplitTunneling $True -PluginApplicationID
SonicWALL.MobileConnect_e5kpm93dbe93j -CustomConfiguration $sourceXml
TodeleteaVPNconnection,usethePowerShellcommandRemove-VPNConnection,specifyingtheVPN
connectionusingthe-nameoption.Forexample:
PS C:\> Remove-VpnConnection –Name VPN
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
14
ConfiguringVPNConnectionCustomXMLSettings
UsingPowerShell,itispossibletoconfigureadvancedsettingsfortheMobileConnectVPNplugin.Thissection
describeseachindividualcu stomXMLoptionandprovidesexamplesofhowtoconfigurethesesettingsusing
PowerShell.
•ServerPort—<Port>4443</Port>‐serverport(optional,defaultis443)
DebugLogging—<DebugLogging>true</DebugLogging>‐enabledebuglogginginplug
in(optional,
defaultfalse).
•PacketCapture—<PacketCapture>true</PacketCapture>‐enablepacketcapture(optional,defaultfalse)
•WindowsNativeAuthenticationUI—<WindowsAuthUI>false</WindowsAuthUI>‐disableWindows
nativeauthenticationUI(optional,defaulttrue).
•ParseDomainfromUsernamefield—<UsernameHasDomain>false</UsernameHasDomain>‐Parseout
DomainfieldfromUsernamefieldinWindowsAuthdialog(optional,defaulttrue).Usernameshouldbe
enteredintheformat
<Username>@<Domain> or<Domain>\<Username>.ForSMA100Series/SRA
andFirewallconnections,theDomainportionisusedfortheDomainfield.
•WindowsSingleSignOn<SingleSignOn>false</Singl eSignOn>‐DonotsetSSOflagto
RequestCredentials()(optional,defaulttrue).
PowerShellExamplesforCustomizingVPN
Connections
Enabledebuglog ging:
PS C:\> $xml = "<MobileConnect><DebugLogging>true</DebugLogging></
MobileConnect>"
PS C:\> $sourceXml=New-Object System.Xml.XmlDocument
PS C:\> $sourceXml.LoadXml($xml)
PS C:\> Add-VpnConnection -Name VPN -ServerAddress vpn.example.com -
SplitTunneling $True -PluginApplicationID
SonicWALL.MobileConnect_e5kpm93dbe93j
-CustomConfiguration $sourceXml
NOTE:IfDebugLog gingisenabled,logsarewrittentothefollowingfile:
C:\Users\<userName>\AppData\Local\Packages\SonicWALL.MobileConnect
_e5kpm93dbe93j\LocalState\Logs\MobileConnect.log
NOTE:IfPacketCaptureisenabled,thepacketcaptureisinthefollowingfiles:
ConnectionstoSMA1000Series/EClassSRAappliances:
C:\Users\<userName>\AppData\Local\Packages\SonicWALL.MobileConnect
_e5kpm93dbe93j\LocalState\Logs\MobileConnect.pcap
ConnectionstoSMA100Series/SRAandFirewallappliances:
C:\Users\<userName>\AppData\Local\Packages\SonicWALL.MobileConnect
_e5kpm93dbe93j\LocalState\Logs\MobileConnect.ppp.pcap
NOTE:<UsernameHasDomain>onlyappliesifW indowsAuthUIisenabled
NOTE:<SingleSignOn>willnotapplyfortheusername&passwordcustomauthenticationprompt
(WindowsAuthUIsettofalse)
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
15
Enabledebugloggingandpack etcapture:
PS C:\> $xml = "<MobileConnect><DebugLogging>true</
DebugLogging><PacketCapture>true</PacketCapture></MobileConnect>"
PS C:\> $sourceXml=New-Object System.Xml.XmlDocument
PS C:\> $sourceXml.LoadXml($xml)
PS C:\> Add-VpnConnection -Name VPN -ServerAddress vpn.example.com -
SplitTunneling $True -PluginApplicationID
SonicWALL.MobileConnect_e5kpm93dbe93j
-CustomConfiguration $sourceXml
SpecifyNonstandardportforVPNconnection:
PS C:\> $xml = "<MobileConnect><Port>4433</4433></MobileConnect>" PS C:\>
$sourceXml=New-Object System.Xml.XmlDocument
PS C:\> $sourceXml.LoadXml($xml)
PS C:\> Add-VpnConnection -Name VPN -ServerAddress vpn.example.com -
SplitTunneling $True -PluginApplicationID
SonicWALL.MobileConnect_e5kpm93dbe93j
-CustomConfiguration $sourceXml
ConfiguringAdvancedVPNConnectionSettings
Thissectionincludesthefollowingtopics:
ConfiguringSMA1000Series/EClassSRAConnectionSettingsonpage15
ConfiguringSMA100Series/SRAandFirewallConnectionSettingsonpage16
ConfiguringSMA1000Series/EClassSRAConnection
Settings
ThefollowingsettingsareapplicabletoVPNconnectionswithSMA1000Series/EClassSRAappliances:
•EncapsulatedSecurityPayload—<ESP>true</ESP>‐Enable ESPmode(optional,defaultfalse)
Compression—<Compression>false</Compression>‐Disablelz4compression(optional,defaulttrue)
•NetworkConflictResolutionMode—<NCR>Local</NCR>‐SetNetworkConflict
Resolution(NCR)mode(optional,default'Admin',othervalues'Remote'or
'Local')
•LoginGroupCaching—<CacheLoginGroup>true</CacheLoginGroup>‐EnableLogin
Groupselectioncaching(optional,defaultfalse)
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
16
ConfiguringSMA100Series/SRAandFirewall
ConnectionSettings
ThefollowingsettingsareapplicabletoVPNconnectionswithSMA100Series/SRAorFirewallappliances:
•CasesensitiveDomainMatching—<DomainMatchCaseSensitive>true</DomainMatchCaseSensitive>‐
PerformcasesensitivematchforuserenteredDomainfieldagainstVPNserverDomain(optional,
defaultfalse)
•MaxLoginRetries—<MaxLoginRetries>0</MaxLoginRetries>‐(optional,default2‐totalof3login
attemptsallowed)
•Require
SmartCardCertificate—<SmartCardRequired>true</SmartCardRequired>‐requireclient
certificatetobeSmartCard(CertificateQuery>HardwareOnlyflagmustbeset)(optional)
ClientCertificateIssuerCA—<ClientCertIssuerCA>testing.testsslvpn.com</ClientCertIssuerCA>‐filter
setofclientcertificatesinstalledonWindows10bytheIssuerCA(optional)
AutomaticallySelectClientCertificate<ClientCertAutoSelect>true</ClientCertAutoSelect>‐
automaticallyselectasingleclientcertificatewithoutpromptingthe
userforverification(optional,
defaultfalse)
ClientCertificateThumbprint
<ClientCertThumbprint>bea9275b806262dea611059efc8c2fa55 7d8ee10</ClientCertThumbprint>‐
automaticallyselecttheclientcertificatethatmatchesthegivencertificateThumbprint(optional)
ConfiguringVPNConnectionTriggersin
Windows10
VPNconnectiontriggerscanbeconfiguredusingPowerShelltoautomaticallyconnectaVPNconnectionwhen
anapplicationislaunched,orwhenaclientattemptstoaccessaresourcewithinaspecifiedDNSnamespace.In
addition,trustednetworkscanbeconfiguredtopreventaVPNconnectionfrombeinginitiatedwhenclient
devices
arealreadywithinthetrustednetworkandtheVPNisnotneeded.Pleaseref ertoMicrosofts
documentationonthefollowingcommands:
•AddVpnConnectionTriggerApplication
(seehttp://technet.microsoft.com/enus/library/dn296460%28v=wps.630%29.aspx)
TheAdd-VpnConnectionTriggerApplicationcommandaddsapplicationstoaVPNconnection
object.TheapplicationsautomaticallytriggeraVPNconnectionwhenlaunched.
•AddVpnConnectionTrig gerDnsConfiguration
(seehttp://technet.microsoft.com/enus/library/dn262650%28v=wps.630%29.aspx)
The
Add-VpnConnectionTriggerDnsConfigurationcommandaddsaDNSsuffixornametothe
DNStriggerpropertiesforaclient.IfyouspecifyaDNSIPaddressforthesuffixorname,whentheclient
accessesaresourcewithinthe suffix,theclientstartsaVPNconnection.IfyoudonotspecifyaDNSIP
addressforaDNSsuffixorname,accessingthesuffixornamedoesnottriggertheVPNconnection.
NOTE:Defaultbehavioristhatacaseinsensitivematchisperformed.Onlyappliesif
<WindowsAuthUI>isenabledand<UsernameHasDomain>isenabled.
NOTE:TheWinRTStreamSocketAPIinWindows10doesnotcurrentlyprovidethelistofIssuerCA
certificatesfromtheSSLserver,sothismaybeusedasaworkaroundtofilterthelist.
SonicWallMobileConnectforWindows10UserGuide
ConfiguringVPNConnections
17
•AddVpnConnectionTriggerTrustedNetwork
(seehttp://technet.microsoft.com/enus/library/dn262638%28v=wps.630%29.aspx)
TheAdd-VpnConnectionTriggerTrustedNetworkcommandaddsDNSsuffixesastrusted
networkstotheVPNprofile.WhenaDNSsuffixthatyouaddtotheVPNprofileispresentonthephysical
interfaceontheclient,theVPNconnectiondoesnotstarteveniftheclienttriestoaccess
anapplicationthat
ispartoftriggeringpropertiesortriestoaccessaresourcethatispartofDNSsuffixconfiguredfortriggering.
SonicWallMobileConnectforWindows10UserGuide
MonitoringVPNConnectionsinWi ndows
4
18
MonitoringVPNConnectionsinWindows
VPNconnectionscanbemonitoredinWindows10usingthenativesetofWindowsutilities,includingCMDshell
commands,suchasipconfigandroute,andapplicationssuchasTaskManager,ResourceMonitor,andtheEvent
Viewer.
Thissectionincludesthefollowingtopics:
DisplayingVPNConnectionNetworkInformationonpage18
MonitoringConnectionsintheWindowsTaskManageronpage21
DisplayingVPNConnectionNetwork
Information
Thefollowingsectionsincludeexamplesusingcommandlineutilitiestoshowdetailednetworkinformation:
DisplayingIPv4NetworkInformationonpage18
DisplayingIPv6NetworkInformationonpage19
DisplayingRoutingInformationonpage19
DisplayingDNSInformationonpage20
DisplayingIPv4NetworkInformation
Thefollowingisanexampleshowing IPv 4networkinformation:
C:\> ipconfig /all
Windows IP Configuration
PPP adapter VPN
Connection-specific DNS Suffix. . : example.com
Description . . . . . . . . . . . : VPN
Physical Address. . . . . . . . . :
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.200.61(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Enabled
Connection-specific DNS Suffix Search List : example.com
SonicWallMobileConnectforWindows10UserGuide
MonitoringVPNConnectionsinWi ndows
19
DisplayingIPv6NetworkInformation
Thefollowingisanexampleshowing IPv 6networkinformation:
C:\> ipconfig /all
Windows IP Configuration
PPP adapter VPN
Connection-specific DNS Suffix. . : example.com
Description . . . . . . . . . . . : VPN
Physical Address. . . . . . . . . :
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . :
2008:192:168:200:1:1:1:6(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.255
Default Gateway . . . . . . . . . :
DHCPv6 IAID. . . . . . . . . . . . : 452990301
DHCPv6 Client DUID . . . . . . . . :
00-01-00-01-1-BD-D7-43-00-15-5D-7E-C4-43
NetBIOS over Tcpip. . . . . . . . : Enabled
Connection-specific DNS Suffix Search List : example.com
DisplayingRoutingInformation
Thefollowingisthecommandtoshowroutinginformation:
C:\> route PRINT
SonicWallMobileConnectforWindows10UserGuide
MonitoringVPNConnectionsinWi ndows
20
DisplayingDNSInformation
Thefollowingisanexampleshowing DNSinformation:
C:\> netsh name show effectivepolicy
DNS Effective Name Resolution Policy Table Settings
Note: DirectAccess settings are inactive when this computer is
inside a corporate network.
Settings for .example.com
-----------------------------------------------------------------
-----
Generic (DNS Servers):
192.168.200.20
192.168.200.21
Generic (VPN Trigger): disabled
Settings for vpn.example.com
-----------------------------------------------------------------
-----
Generic (DNS Servers):
Generic (VPN Trigger): disabled
NOTE:TheproperDNSinformationfortheVPNconnectionisdisplayedusingthenetsh name show
effective policycommand.TheipconfigcommanddoesnotshowthecompletesetofDNS
informationandshouldnotbereliedupon.
/