
SonicWallSMAConnectTunnel12.0DeploymentPlanningGuide
PlanningYourVPN 19
WebResources
AnyWebresource—suchasaWebapplication,aWebportal,oraWebserver—canbedefinedasaURL
resource(theyarespecifiedinAMCusingthestandardhttp://orhttps://URLsyntax).Examplesinclude
MicrosoftOutlookWebAccessandotherWeb‐basede‐mailprograms,Webportals,corporateintranets,and
standardWebservers.
DefiningaWebresourceasaURLprovidesseveraladvantages:
•YoucancreateaWebshortcutonWorkPlacetogiveusersquickaccess.
•YoucandefineveryspecificaccessrulestocontrolwhichuserscanaccesstheURL.
•Youhavetheoptionofobscuring(or“aliasing”)theinternalhostnamesoitisnotpubliclyexposed.
•Youcanblockattachmentsfrombeingdownloadedtountrusteddevices,orpreventaWeb‐based
applicationfromdisplayingrestricteddatatountrusteddevices.
WebtrafficisproxiedthroughtheWebproxyservice,asecuregatewaythroughwhichuserscanaccessprivate
WebresourcesfromtheInternet.
Client/ServerResources
Client/serverresourcesencompassapplications,fileservers,andmultipleWebresourcesandarespecifiedin
AMCusingeitheradomain,subnet,IPrange,hostname,orIPaddress:
• Client/serverapplicationsinclude“traditional”applicationsdevelopedforaparticularoperatingsystem,
orthin‐clientapplicationsthatareWeb‐based.
•NetworksharesincludeWindowsfileserversorfileshares.Networksharesareaccessibleusingeither
OnDemandorConnectTunnel.(ToaccessanetworkshareusingaWebbrowser,youmustinsteaddefine
itasafilesystemresource.)
•Sourcenetworksarereferencedinanaccessruletopermitordenyaconnectiontoadestination
resourcebasedonthelocationfromwhichtherequestoriginates.Forexample,youmightpermit
connectionsonlyfromaparticulardomain,orpermitthemonlyfromaspecificIPaddress.
•GraphicalterminalagentscanbeaddedtoWorkPlaceasshortcutsthatprovideaccesstoaterminal
server(orCitrixserverfarm)usingaWindowsTermin a l ServicesorCitrixclient.
•MultipleWebresourcesonyournetwork—whetherinadomain,subnet,orIPrange—canbedefined.
ThisisaconvenientwayforyoutoadministermultipleWebserversfromasingleresourceinAMC.For
example,ifyouspecifyadomain(andcreatetheappropriateaccessrule),usersareabletousetheir
WebbrowserstoaccessanyWebresourcescontainedwithinthatdomain.TheycanalsouseOnDemand
orConnectTunneltogettothoseresources.
Onthedownside,however,youruserscannotaccessthoseresourcesfromashortcutonWorkPlace;
instead,theymustknowtheinternalhostnameoftheresource.IftheWebproxyagentisrunning,they
canenteranyURLdirectlyinthebrowser.However,intranslatedmode,usersmustmanuallytypeURLs
intheIntranetAddressboxinWorkPlace.
Withsuchawidescopeofresourcedefinitions—frombroadresourcessuchasadomainorsubnet,downtoa
singlehostorIPaddress—youmaywonderhowbesttodefineyournetworkresources.Broadresource
definitionssimplifyyourjobassystemadministrator,andaretypicallyusedwhenmanagingaremoteaccess
VPNwithanopenaccesspolicy.Forexample,youcoulddefineyourinternalDNSnamespaceasadomainand
createasinglepolicyrulegrantingemployeesaccessprivileges.
Ontheotherhand,amorerestrictivesecuritypolicyrequiresyoutodefinenetworkresourcesmorenarrowly.
ThisapproachistypicallyusedwhenadministeringapartnerVPN.Forexample,toprovideanexternalsupplier
withaccesstoaninventoryapplication,youmightspecifyitshostnameasaresourceandcreateapolicyrule
specificallygrantingthesupplieraccessprivileges.