SonicWallSecureMobileAccess6200/7200GettingStartedGuide
15
Inbothconfigurations,incomingrequeststotheSMA6200/
7200services—includingHTTP/StrafficfortheWebproxy
service—aresentoverport80(HTTP)andport443(HTTPS).
TrafficfromtheOnDemandagentisalwayssentoverport443.
Becausemostnetworksareconfiguredtoenabletrafficover
theseports,youshould
notneedtoreconfigurefirewallson
yournetwork.
Youshouldinstalltheapplianceinalocationwhereitcan
connecttoresourcesonyournetwork,including:
• Applicationserversandfileservers,includingWeb
servers,client/serverapplications,andWindowsfile
servers.
• Externalauthenticationrepositories(suchasanLDAP,
MicrosoftActiveDirectory,or
RADIUSserver).
• OneormoreDomainNameSystem(DNS)servers.
• Optionally,aWindowsInternetNameService(WINS)
server.ThisisrequiredforbrowsingWindowsnetworks
usingWorkPlace.
Althoughnotrequired,enablingtheappliancetocommunicate
withtheseadditionalresourcesprovidesgrea terfunctionality
andeaseofuse:
• NetworkTimeProtocol(NTP)
serverforsynchronizing
thetimeontheappliance.
• Externalserverforstoringsyslogoutput.
• Administrator’sworkstationforsecureshell(SSH)
access.
Youcanconfiguretheappliancetouseaself‐signedserver
certificate,or,forenhancedsecurity,youcanobtaina
certificatefromacommercialcertificateauthority(CA).For
moreinformation,
refertotheSMAAdministrationGuide.
CAUTION:TheSMA6200/7200appliancedoesnot
providefullfirewallcapabilitiesandshouldbesecured
behindafirewall.Runningwithoutafirewallmakesthe
appliancevulnerabletoattacksthatcancompromise
securityanddegradeperformance.