Quick Reference Guide

Table Of Contents
Chapter 7: Managing Users, Authentication, and Certificates | 116
Managing Users, Authentication, and
Certificates
7
This chapter contains the following sections:
Adding Authentication Domains, Groups, and Users” on this page.
“Managing Certificates” on page 124.
Adding Authentication Domains, Groups, and Users
You must create name and password accounts for all users who will connect to the VPN
firewall. This includes administrators and SSL VPN clients. Accounts for IPsec VPN clients
are only needed if you have enabled Extended Authentication (XAUTH) in your IPsec VPN
configuration.
Users connecting to the VPN firewall must be authenticated before being allowed to access
the VPN firewall or the VPN-protected network. The login window presented to the user
requires three items: a user name, a password, and a domain selection. The Domain
determines the authentication method to be used and, for SSL VPN connections, the portal
layout that will be presented.
Note: IPsec VPN users will always belong to the default domain
(geardomain) and are not assigned to groups.
Except in the case of IPsec VPN users, when you create a user account, you must specify a
group. When you create a group, you must specify a domain. Therefore, you should create
any needed domains first, then groups, then user accounts.