This topic describes how to set up users and groups for remote VPN access. Defining remote VPN clients consists of the following steps:
- Creating users and
groups for remote VPN clients—Specify and configure user
accounts that are allowed to connect to Forefront TMG as remote VPN
clients. Users can be identified as Remote Authentication Dial-In
User Service (RADIUS) users, or as Windows users.
- Configuring domain
groups for remote access—Specify the domain groups allowed VPN
access.
- Enabling user
mapping for clients authenticating via RADIUS or EAP
(optional)—Enable user mapping if you intend to use RADIUS or
EAP authentication, and the Forefront TMG computer is a member of
the domain.
Creating users and groups for remote VPN clients
Note that you configure groups and users in the Microsoft Management Console "Computer Management".
To create users and groups
-
Click Start, click Run, type compmgmt.msc, and then press ENTER.
-
In the Computer Management window, click Local Users and Groups, right-click Groups, and then select New Group.
-
In New Group, type a name for the group, and then click Create, and click Close.
-
Click Users. For each user that you want to have remote VPN access, do the following:
- Double-click the user to display its properties.
- On the Member Of tab, click Add.
- In Enter the object names to select, type the name of
the group, and then click OK.
- On the Dial-in tab, select Control access through
Remote Access Policy, and then click OK.
- Double-click the user to display its properties.
Important: |
---|
Only users with the dial-in properties configured can use Forefront TMG for remote VPN client access. |
Note: |
---|
When you configure VPN client access to specify which local
groups have remote access, you can add only the following groups:
|
Note: |
---|
In native-mode Active Directory domains, domain accounts have dial-in access controlled by Remote Access Policy by default. In non-native mode (mixed) Active Directory domains, you must enable dial-in access for each domain user account requiring VPN access. For each account, select Allow Access on the Dial-in tab. |
Configuring domain groups for remote access
Use the following procedure to allow members of domain groups to access the VPN remotely.
To allow remote access for members of domain groups
-
In the Forefront TMG Management console, in the tree, click the Remote Access Policy (VPN) node.
-
In the details pane, click the VPN Clients tab.
-
On the Tasks tab, click Configure VPN Client access.
-
On the Groups tab, click Add.
-
Type the names of users or groups that are allowed access to the VPN Clients network.
Enabling user mapping for clients authenticating via RADIUS or EAP (optional)
Use the following procedure to ensure that Firewall policy access rules that apply to user sets for Windows users and groups, are also applied to VPN clients authenticating to your network, via RADIUS or EAP. To do this, you must enable user mapping.
To enable user mapping
-
In the Forefront TMG Management console, in the tree, click the Remote Access Policy (VPN) node.
-
In the details pane, click the VPN Clients tab.
-
On the Tasks tab, click Configure VPN Client Access.
-
On the User Mapping tab, click Enable User Mapping.
-
If the user name to be mapped does not include a domain name, select When username does not contain a domain, use this domain, and type the name of the domain to use.
Note: |
---|
|
Next Steps
Related Topics
Copyright © 2009 by Microsoft Corporation. All rights reserved.