Novell Access Manager 3.1 SP4 User guide

Category
VPN security equipment
Type
User guide
www.novell.com/documentation
SSL VPN User Guide
Access Manager 3.1 SP5
January 2013
Legal Notices
Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthisdocumentation,andspecifically
disclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,
reservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,withoutobligationtonotifyany
personorentityofsuchrevisionsorchanges.
Further,Novell,Inc.,makesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsany
expressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.,reservestheright
to
makechangestoanyandallpartsofNovellsoftware,atanytime,withoutanyobligationtonotifyanypersonorentityof
suchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreeto
complywithallexportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexportorimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.
exportlaws.Youagreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.SeetheNovellInternationalTrade
ServicesWebpage(http://www.novell.com/info/exports/)formoreinformationonexportingNovellsoftware.Novellassumes
noresponsibilityforyourfailuretoobtainanynecessaryexportapprovals.
Copyright©2013Novell,
Inc.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,storedona
retrievalsystem,ortransmittedwithouttheexpresswrittenconsentofthepublisher.
Novell, Inc.
1800 South Novell Place
Provo, UT 84606
U.S.A.
www.novell.com
OnlineDocumentation:ToaccessthelatestonlinedocumentationforthisandotherNovellproducts,seetheNovell
DocumentationWebpage(http://www.novell.com/documentation).
Novell Trademarks
ForNovelltrademarks,seetheNovellTrademarkandServiceMarklist(http://www.novell.com/company/legal/trademarks/
tmlist.html).
Third-Party Materials
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Contents 3
Contents
About This Guide 5
1 Overview of SSL VPN 7
1.1 Access Modes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7
1.1.1 Kiosk Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
1.1.2 Enterprise Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2 Client Machine Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2.1 Linux Requirements. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8
1.2.2 Macintosh Requirements. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
1.2.3 Windows Requirements. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
2 Accessing SSL VPN in Kiosk Mode 11
2.1 Accessing the SSL VPN User Portal . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
2.2 Switching from Kiosk Mode to Enterprise Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13
3 Accessing SSL VPN in Enterprise Mode 15
3.1 Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15
3.2 Accessing SSL VPN When You Are an Admin or root User . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
3.3 Accessing SSL VPN as a Non-Admin User . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.4 Switching from Enterprise Mode to Kiosk Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19
3.5 Enabling the Sudo Command for Standard Users in the Mac OS . . . . . . . . . . . . . . . . . . . . . . . . . . .19
4 Accessing Published Citrix Applications through SSL VPN 21
4.1 Accessing Published Citrix Applications in Kiosk Mode. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
4.2 Accessing Published Citrix Applications in Enterprise Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .21
5 Using SSL VPN 23
5.1 Using the SSL VPN Home Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .23
5.2 Using the Policies Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
5.3 Configuring the Cleanup Options. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
5.4 Viewing SSL VPN Logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
5.5 Enabling Applications for SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
5.5.1 Enabling Linux Applications for SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
5.5.2 Enabling Macintosh Applications for SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
5.5.3 Enabling Terminals for SSL. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
5.6 Logging Out of the Active SSL VPN Session. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
5.7 Using the Sandbox Feature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .28
5.8 Error. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
5.9 Connecting after the Session Timeout Period . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
5.10 Downloading the Applet on Internet Explorer. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
4 Novell Access Manager 3.1 SP5 SSL VPN User Guide
A Error Messages 31
B Troubleshooting SSL VPN 49
B.1 SSL VPN Fails to Load If Firefox 3.0 Is Used on Vista 64-bit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .50
B.2 Error: Failed to Fetch CIC Policy from the Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .50
B.3 Stability Issues when You Use a Firefox Browser on a Vista 64-Bit Machine . . . . . . . . . . . . . . . . . . 50
B.4 Unable to Connect to SSL VPN Because of the OpenVPN Error . . . . . . . . . . . . . . . . . . . . . . . . . . .50
B.5 The SSL VPN Applet Fails to Download on a SLED 11 64-Bit Machine . . . . . . . . . . . . . . . . . . . . . .51
B.6 Unable to Connect to SSL VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
B.7 Unable to Connect to SSL VPN from the Same Internet Explorer Browser Session. . . . . . . . . . . . .52
B.8 The SSL VPN Connection Fails with an OpenVPN Connection Error . . . . . . . . . . . . . . . . . . . . . . . .52
B.9 The Browser Cache Is Not Cleared When Multiple Tabs Are Used in Vista . . . . . . . . . . . . . . . . . . .52
B.10 Failed to Connect to SSL VPN. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .52
B.11 Mozilla Firefox Browser Displays an “X” Mark . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
B.12 Applications Are Not Enabled from the Terminal after Running the su Command . . . . . . . . . . . . . . 53
B.13 SSL VPN Session Disconnects after Approximately 10 Hours . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
B.14 Error: Failed to Download the SSLVPN Files from Gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .53
B.15 Unable to Connect After the Previous Connection Ended Abruptly. . . . . . . . . . . . . . . . . . . . . . . . . . 54
B.16 SSL VPN Client Displays the Nonsecure Items Dialog Box. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .54
B.17 Clear Cache Option Retains Some Image Files in the Temporary Internet Folder . . . . . . . . . . . . . .54
B.18 SSL VPN Fails to Retrieve Help Pages When There Is an Error. . . . . . . . . . . . . . . . . . . . . . . . . . . .55
B.19 The Browser Becomes Non-Responsive If Clear Browser Private Data Is Repeatedly Clicked . . . .55
B.20 SSL VPN Issues with the Latest Versions of JRE 1.6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .55
B.21 Unable to Access Protected HTTP Applications through a Safari Browser . . . . . . . . . . . . . . . . . . . . 55
B.22 Linux Browser Issues in Kiosk Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .55
B.23 Issues with the Intlclock Toolbar Application . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .56
B.24 Socks Client Logs Are Displayed under Service Logs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
B.25 Connection Fails in SSL VPN If the Root User Password Is Not Set in Macintosh . . . . . . . . . . . . . . 56
B.26 SSL VPN Log In Displays Error . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
B.27 SSL VPN Fails to Connect after SP2 Upgrade due to IP Address Assignment Error . . . . . . . . . . . . 56
B.28 Applications do not Use DNS Configured at SSL VPN Server When DNS is Manually Configured at Mac
Leopard Machine . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
About This Guide 5
About This Guide
ThisdocumentisintendedtohelpyouunderstandandusetheSSLVPNuserportal.Itcontainsthe
followinginformation:
Chapter 1,“OverviewofSSLVPN,onpage 7
Chapter 2,AccessingSSLVPNinKioskMode,”onpage 11
Chapter 3,AccessingSSLVPNinEnterpriseMode,”onpage 15
Chapter 4,AccessingPublishedCitrixApplications
throughSSLVPN,”onpage 21
Chapter 5,“UsingSSLVPN,”onpage 23
Appendix B,“TroubleshootingSSLVPN,”onpage 49
Appendix A,“ErrorMessages,”onpage 31
Audience
ThisguideisintendedforNovellAccessManagerSSLVPNendusers.
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualand theotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgotowww.novell.com/documentation/feedback.htmlandenteryour
commentsthere.
Documentation Updates
ForthemostrecentversionoftheSSLVPNUserGuide,visittheNovellAccessManager
DocumentationWebsite(http://www.novell.com/documentation/novellaccessmanager31).
Additional Documentation
NetIQAccessManager3.1SP5SSLVPNServerGuide
NovellAccessManager3.1SP4InstallationGuide
NovellAccessManager3.1SP5SetupGuide
NovellAccessManager3.1SP5AdministrationConsoleGuide
NetIQAccessManager3.1SP5IdentityServerGuide
NetIQAccessManager3.1SP5AccessGatewayGuide
Documentation Conventions
InNovelldocumentation,agreaterthansymbol(>)isusedtoseparateactionswithinastepand
itemsinacrossreferencepath.
6 Novell Access Manager 3.1 SP5 SSL VPN User Guide
1
Overview of SSL VPN 7
1
Overview of SSL VPN
TheNovellAccessManagerSSLVPNallowsyoutouseaWebbrowsertoaccesscorporateresources
securelyfromaremotesite.ItusesaSecureSocketLayer(SSL)withavirtualprivateconnection
(VPN).Itisaclientlesssolution,anditeliminatestheneedtoinstallorconfigureaVPN
clienton
yourdesktoporlaptop.Thisgivesyoutheflexibilitytoaccessthecorporateresourcesfromalaptop,
ahomecomputer,oraWebbrowsingkiosk.
WhenyouaccesstheSSLVPNserverthroughaWebbrowser,aJavaappletoranActiveXcontrolis
installedonyourmachine
afterthesuccessfulconnection.Thisencryptsthetrafficpassingthrough
thetunnelandsendsittotheSSLVPNserver.
ThissectiondescribesthefollowingfeaturesofSSLVPN:
Section 1.1,AccessModes,”onpage 7
Section 1.2,“ClientMachineRequirements,”onpage 8
1.1 Access Modes
TheNovellSSLVPNusesbothclientlessandthinclientaccessmethods.Theclientlessmethodis
calledtheKioskmodeSSLVPNandthethinclientmethodiscalledtheEnterprisemodeSSLVPN.
Section 1.1.1,“KioskMode,”onpage 7
Section 1.1.2,“EnterpriseMode,”onpage 8
1.1.1 Kiosk Mode
Kioskmodeistheusualchoiceforcomputersnotcontrolledbytheorganization,suchashome
computersandcomputersinWebbrowsingkiosks.WhenyouconnecttoSSLVPNinKioskmode,
onlyalimitedsetofapplicationsareenabledfor SSL.
ApplicationsthatwereopenedbeforetheSSLVPNconnection
wasestablishedarenotenabledfor
SSL.YoumustmanuallyenabletheapplicationsthatwereopenedbeforetheSSLVPNconnection.
Formoreinformation,seeSection 5.5,“EnablingApplicationsforSSL,”onpage 27.
YouareconnectedtoSSLVPNinKioskmodeif:
Youdonothaveadministratorrightsor
root
privilegestotheworkstation,andyoudonot
knowthecredentialsoftheadministratoror
root
userofthemachine.
Youhaveadministratorrightsor
root
privilegestotheworkstation,butyouarerequiredbythe
systemadministratortoconnectinKioskmodeonly.
FormoreinformationonusingtheKioskmode,seeChapter 2,AccessingSSLVPNinKioskMode,”
onpage 11.
8 Novell Access Manager 3.1 SP5 SSL VPN User Guide
1.1.2 Enterprise Mode
TheEnterprisemodeistheusualchoiceforcomputersthatarecontrolledbytheorganization,such
asnotebooksprovidedbytheorganizationforemployees.WhenyouconnecttoSSLVPNin
Enterprisemode,allapplicationsareenabledforSSL,regardlessofwhethertheywereopenedbefore
orafterconnectingtotheSSL
VPN.Thisincludesyourdesktopapplicationsandtoolbarapplications.
YouareconnectedtoSSLVPNinEnterprisemodeif:
Youare theadministratoror
root
userofaworkstation,ifthesystemadministratorhasnot
requiredyoutoconnectinKioskmodeonly.
Youarenottheadministratoror
root
userofaworkstation,butyouknowthecredentialsofthe
administratoror
root
user.
IfsomeonewithadministratoraccesshaspreinstalledtheSSLVPNthinclientcomponentson
yourmachine,youcanconnecttoSSLVPNinEnterprisemode.Formoreinformationon
preinstallingthethinclientcomponents,seePreinstallingtheSSLVPNClientComponentsin
theNetIQAccessManager3.1SP5
SSLVPNServerGuideNetIQAccessManager3.1SP5SSLVPN
ServerGuide.
FormoreinformationonusingEnterprisemode,seeChapter 3,AccessingSSLVPNinEnterprise
Mode,”onpage 15.
1.2 Client Machine Requirements
Thissectionexplainstheoperatingsoftwareandbrowserrequirementsfortheclientmachine,in
ordertoaccesstheSSLVPNuserportal.
Section 1.2.1,“LinuxRequirements,”onpage 8
Section 1.2.2,“MacintoshRequirements,”onpage 9
Section 1.2.3,“WindowsRequirements,”onpage 9
1.2.1 Linux Requirements
WhenyouaccesstheSSLVPNuserportalintheLinuxaJavaappletisdownloadedtotheclient
machine.Thefollowingtableliststhesupportedversionsofoperating softwareandbrowsersforthe
Linuxenvironment:
Table 1-1 SupportedLinuxConfigurations
Component Requirement
Operating Systems
SUSE
Linux Enterprise Desktop (SLED) 10.0 and SLED 11 are supported for 32-
bit and 64-bit platforms.
OpenSSL 0.9.7 or higher. If your OpenSSL version is higher than 0.9.7, you must install an
OpenSSL 0.9.7 compatible library.
Shells bash
xterm
Browser Mozilla Firefox 2.x, 3.0.X and 3.x
Java and JavaScript enabled
Overview of SSL VPN 9
NOTE:IfyouareusingSLED11.064bitclient,makesurethatyouhavethelatestJREinstalledon
yourmachine.
1.2.2 Macintosh Requirements
WhenyouaccesstheSSLVPNuserportalintheMacintoshenvironment,aJavaappletis
downloadedtotheclientmachine.Thefollowingtableliststhesupportedversionsofoperating
softwareandbrowsersintheMacenvironment:
Table 1-2 SupportedMacintoshConfigurations
NOTE:GroupWise7.0and8.0doesnotworkwhenSSLVPNKioskmodeisrunningonMacintosh
TigerOS.
1.2.3 Windows Requirements
WhenyouaccesstheSSLVPNuserportalintheWindowsenvironment,anActiveXcontrolis
downloadedtotheclientmachine.IfyouwanttodownloadtheJavaappletonyourmachineinstead
oftheActiveXcontrol,theadministratorneedstoperformsomeserversideconfigurations.Formore
information,referto
ConfiguringSSLVPNtoDownloadtheJavaAppletonInternetExplorerin
theNetIQAccessManager3.1SP5SSLVPNServerGuide.
ThefollowingtableliststhesupportedversionsofoperatingsoftwareandbrowsersintheWindows
environment:
Sun JRE 1.5.0_11 or higher
Component Requirement
Component Requirement
Operating System Mac PPC 10.4 Tiger
Mac Intel 10.5 Leopard
Mac OSX 10.6 Snow Leopard
OpenSSL 0.9.7
Shell bash
Browser Mac Safari 2.0.4 Build 412 or higher
Firefox 2.x, 3.0.X or 3.5
Java and JavaScript enabled
Sun JRE 1.5.0_11 or higher
10 Novell Access Manager 3.1 SP5 SSL VPN User Guide
Table 1-3 SupportedWindowsConfigurations
Component Requirement
Operating System Windows XP SP2/SP3 - 32-bit and 64-bit
Windows Vista - 32-bit and 64-bit
Windows 7 32-bit and 64-bit
NOTE: Windows 64-bit is supported only in Enterprise Mode
Browser Internet Explorer 7.0 and 8.0
Mozilla Firefox 2.x, 3.0.x, 3.5, 3.6 x
NOTE: Do not use Windows Explorer to run SSL VPN.
Sun JRE 1.4.1 or higher
NOTE: If you are using Firefox 3.6, you must have Java SE 6 update 10 or
higher.
2
Accessing SSL VPN in Kiosk Mode 11
2
Accessing SSL VPN in Kiosk Mode
Kioskmodeistheusualchoiceforcomputersnotcontrolledbytheorganization,suchashome
computersandcomputersinWebbrowsingkiosks.
IntheKioskmodeofSSLVPN,onlythoseapplicationsthatareopenedafterconnectingtotheSSL
VPNserverareenabledforSSL.Youmustmanuallyadd
theapplicationsthatwereopenedbefore
connectingtoSSLVPNinordertoenablethemforSSL.Formoreinformationonmanuallyadding
theapplications,seeSection 5.5,“EnablingApplicationsforSSL,”onpage 27.
ThissectionhasthefollowinginformationonaccessingSSLVPNinKioskmode:
Section 2.1,AccessingtheSSLVPN
UserPortal,onpage 11
Section 2.2,“SwitchingfromKioskModetoEnterpriseMode,”onpage 13
ForinformationonconnectingtotheSSLVPNuserportalinEnterprisemode,seeChapter 3,
AccessingSSLVPNinEnterpriseMode,”onpage 15.
2.1 Accessing the SSL VPN User Portal
1 LogintotheSSLVPNserverbyusingthefollowingURL:
https://<dns_name>/sslvpn/login
Replace<dns_name>withtheDNSnameofyourSSLVPNserver.
2 OntheAccessManagerpage,specifytheusernameandpassword,thenclickOK.
3 ClickYes inthewarningmessagetoacceptanddownloadthesignedActiveXcontrolorJava
appletrequiredfortheSSLVPNclient.TheSSLVPNmodeselectiondialogboxisdisplayed.
12 Novell Access Manager 3.1 SP5 SSL VPN User Guide
4 Dooneofthefollowing:
SelectKioskMode(Current)toconnecttoSSLVPNinKioskmodeforthecurrentsession.
Whenyouselectthisoption,youarepromptedtoentertheusernameandpasswordforthe
administratoruserthenexttimeyoulogin.
ClickKioskMode(Always)toalways
connecttoSSLVPNinKioskmode.Whenyouselect
thisoption,youareconnectedtoSSLVPNinKioskmodeinthesubsequentloginswithout
beingpromptedtoselectthemode.IfyouwanttoconnecttoSSLVPNinEnterprisemode
inoneofthesubseq uent connections,you
candoso.Formoreinformation,seeSection 2.2,
“SwitchingfromKioskModetoEnterpriseMode,”onpage 13.
5 ClickOK.IfyouclickCancelyouare connectedtoSSLVPNinKioskmodeforthecurrent
session.
6 (Conditional)IfyouareanonadminuserandifyouareusingInternetExplorertoconnectto
SSLVPN,clickthelinkdisplayedinoption2ofthe followingscreentoproceedwiththeSSL
VPNconnection.
Thispageisdisplayedbecauseanonadminuserofthemachinecannot
downloadtheActiveX
control,whichisessentialtoestablishtheSSLVPNconnection.Clickingthelinkdownloadsthe
appletonyourmachineandestablishestheconnection.
7 IftheSSLVPNconnectionissuccessful,theSSLVPNHomepageisdisplayed.Makesurethat
youkeepthebrowseropenthroughouttheSSLVPNsession,andcontinuewithStep 8.
or
IftheSSLVPNconnectionfails,anerrormessageisdisplayed.SkiptoStep 9.
Accessing SSL VPN in Kiosk Mode 13
8 Dooneofthefollowing,dependingonwhetheryouareaLinux,Macintosh,orWindowsuser:
Linux:IfyouareaLinuxuser,openanewterminaltolaunchapplications thatneedtobe
enabledforSSL.Formoreinformation,seeSection 5.5.1,“EnablingLinuxApplicationsfor
SSL,”onpage 27.
Macintosh:
IfyouareaMacintoshuser,openanewterminaltolaunchapplications that
needtobeenabledforSSL.Formoreinformation,seeSection 5.5.2,“EnablingMacintosh
ApplicationsforSSL,”onpage 28.
Windows:IfyouareaWindowsuser,openapplicationsthatyouwanttoaccessfromyour
protectednetwork.
9 IftheSSLVPNconnectionfails,clickLogout toclosethesessionandretry.Formoreinformation
ontheseerrormessages,seeAppendix A,“ErrorMessages,”onpage 31
2.2 Switching from Kiosk Mode to Enterprise Mode
IfyouselectedKioskMode(Always)whenyoufirstconnectedtoSSLVPN,youareconnectedtoSSL
VPNinKioskmodeinsubsequentconnections.However,youcanswitchtoEnterprisemodeafter
youconnect.
1 ConnectinKioskmode.
2 ClickExittologoutofthecurrentsession.
3 SelecttheEnableEnterprisemodecheckboxintheExitSSLVPNpage.
4 LoginagaininEnterprisemode.
FormoreinformationonconnectingtoSSLVPNinEnterprisemode,seeChapter 3,Accessing
SSLVPNinEnterpriseMode,”onpage 15.
14 Novell Access Manager 3.1 SP5 SSL VPN User Guide
3
Accessing SSL VPN in Enterprise Mode 15
3
Accessing SSL VPN in Enterprise Mode
TheEnterprisemodeistheusualchoiceforcomputersthatarecontrolledbytheorganization,such
asnotebooksprovidedbytheorganizationforemployees.
WhenyouaccesstheSSLVPNuserportalinEnterprisemode,allapp licationsareenabledforSSL,
whethertheywereopenedbeforeoraftertheSSLVPN
connectionwasmade.
Thissectioncontainsthefollowinginformation onusingtheSSLVPNuserportalinEnterprise
mode:
Section 3.1,“Prerequisites,”onpage 15
Section 3.2,AccessingSSLVPNWhenYouAreanAdminorrootUser,”onpage 15
Section 3.3,AccessingSSLVPNasaNonAdminUser,”onpage 17
Section 3.4,“Switchingfrom
EnterpriseModetoKioskMode,”onpage 19
Section 3.5,“EnablingtheSudoCommandforStandardUsersintheMacOS,”onpage 19
ForinformationonconnectingtotheSSLVPNuserportalinKioskmode,seeChapter 2,Accessing
SSLVPNinKioskMode,”onpage 11.
3.1 Prerequisites
ToconnecttoSSLVPNinEnterprisemode:
YoushouldbeanadminuserintheWindowsenvironmentor
root
userintheLinuxor
Macintoshenvironment,orauserwiththeadministrativeor
root
useraccess.
Ifyouareanonadminoranon
root
useranddonothaveadminor
root
useraccess,youmust
preinstalltheclientcomponents.Formoreinformationonpreinstallingtheclientcomponents,
seePreinstallingtheSSLVPNClientComponentsintheNetIQAccessManager3.1SP5SSL
VPNServerGuide.
Youmust havetherecommendedbrowseroroperatingsoftwareinstalledinyoursystem.
For
moreinformation,seeSection 1.2,“ClientMachineRequirements,”onpage 8.
Ifyouareastandarduser,makesurethatthesudocommandisenabled.Formoreinformation,
seeSection 3.5,“EnablingtheSudoCommandforStandardUsersintheMacOS,”onpage 19.
3.2 Accessing SSL VPN When You Are an Admin or root User
Ifyouareanadminor
root
user,theEnterprisemodeofSSLVPNisenabledbydefaultunlessthe
SSLVPNadministratorhasconfiguredyoutoconnectinKioskmodeonly.
1 LogintotheSSLVPNserverbyusingthefollowingURL:
https://<dns_name>/sslvpn/login
Replace<dns_name>withtheDNSnameofyourSSLVPNserver.
16 Novell Access Manager 3.1 SP5 SSL VPN User Guide
2 OntheAccessManagerpage,specifytheusernameandpassword,thenclickOK.
3 ClickYes inthewarningmessagetoacceptanddownloadthesignedappletcomponents
requiredforSSLVPN.
4 (Conditional)Iftheconnectionissuccessful,theSSLVPNHomepageisdisplayed,allowing
accesstoalltheresourceslistedonthePolicytab.Makesurethatyoudonotclosethisbrowser
duringtheSSLVPNsession.
IftheSSLVPNconnectionfails,anerrormessageisdisplayed.
Accessing SSL VPN in Enterprise Mode 17
5 (Conditional)Ifyouseethiserrormessage,clickLogouttologoutofthesession.Formore
informationontheseerrormessages,seeAppendix A,“ErrorMessages,”onpage 31.
3.3 Accessing SSL VPN as a Non-Admin User
Ifyouareanonadminoranon
root
user,butyouknowthecredentialsoftheadministratoror
root
user,youcanconnecttoSSLVPNinEnterprisemodeasfollows:
1 LogintotheSSLVPNserverbyusingthefollowingURL:
https://<dns_name>/sslvpn/login
Replace<dns_name>withtheDNSnameofyourSSLVPNserver.
2 OntheAccessManagerpage,specifytheusernameandpasswordoftheadministratororthe
root
userofthemachine,thenclickOK.
3 ClickYes todownl oadthesignedappletcomponentsrequiredforSSLVPN.
4 SelectEnterprisemodelogininthedialogboxpromptingyoutoselectamodeofSSLVPN.
18 Novell Access Manager 3.1 SP5 SSL VPN User Guide
5 Specifytheusernameandpasswordoftheadministratoror
root
user,thenclickOK.
Youare connectedtoSSLVPNinEnterprisemodeinsubsequentconnections.Youarenot
promptedfortheadministratoror
root
usernameandpasswordthenexttimeyoulogin.
IfyouclickOKinthedialogboxtoenableEnterprisemodeofSSLVPNandyoulaterwantto
switchtotheKioskmodeonthesamemachine,seeSection 3.4,“SwitchingfromEnterprise
ModetoKioskMode,”onpage 19
6 (Conditional)IfyouareusingtheInternetExplorerbrowserand theActiveXcontrolisnot
installed,clickthetoolbarofthefollowingscreentodownloadtheActiveXcontrol:
7 (Conditional)Iftheconnectionissuccessful,theSSLVPNHomepageisdisplayed,allowing
accesstoalltheresourceslis tedonthePolicypage.Makesurethatyoudonotclosethisbrowser
duringtheSSLVPNsession.
or
Accessing SSL VPN in Enterprise Mode 19
IftheSSLVPNconnectionfails,anerrormessageisdisplayed.Formoreinformationonthese
errormessages,seeAppendixA,“ErrorMessages,”onpage15
3.4 Switching from Enterprise Mode to Kiosk Mode
Ifyouareanonadminornon
root
userandyouenabledtheEnterprisemodeofSSLVPN,youare
connectedtoSSLVPNintheEnterprisemodeinsubsequentlogins.YoucanreturntoKioskmodeon
thesameworkstationduringthenextlogin.
1 ConnectinEnterprisemode.
2 ClickExittologoutofthecurrentsession.
3 SelecttheUninstallEnterprisemodecheckboxontheExitSSLVPNpage.
4 LoginagaininKioskmode.
FormoreinformationonconnectingtoSSLVPNinKioskmode,seeChapter 2,AccessingSSL
VPNinKioskMode,”onpage 11.
3.5 Enabling the Sudo Command for Standard Users in the Mac
OS
NovellSSLVPNusesthe
sudo
commandtogainrootprivilegesfornonrootusersintheMacOS.
ThiscommandisnotenabledbydefaultforstandardusersintheMacOS.
Tomanually enablethecommand:
1 Open
/etc/sudoers
2 Addthefollowinglines:
Defaults targetpw
ALL ALL=(ALL) ALL
3 Saveandclosethefile.
20 Novell Access Manager 3.1 SP5 SSL VPN User Guide
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54
  • Page 55 55
  • Page 56 56
  • Page 57 57
  • Page 58 58

Novell Access Manager 3.1 SP4 User guide

Category
VPN security equipment
Type
User guide

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI