Getting started
SSL VPN allows remote users to securely access a company's resources - internal or otherwise - via the SNS firewall.
An SSL VPN client must be installed on the user’s workstation or mobile device before a VPN tunnel can be set up with the SNS firewall. Communications between the SNS firewall and the user are then encapsulated and protected via an encrypted TLS tunnel.
This tunnel can only be set up if the user is authenticated over a TLS communication channel, and encrypted with shared client and server certificates that have been signed by a certification authority (CA) on the SNS firewall. This solution therefore guarantees confidentiality, integrity and non-repudiation.
This technical note provides details on:
- Enabling and configuring the SSL VPN service on SNS firewalls in version 4.x,
- Implementing zero trust network access (ZTNA) with SNS firewalls in version 4.8 and higher, and Stormshield SSL VPN clients in version 4.0 or higher,
- Installing the Stormshield SSL VPN client in version 4.x, configuring and using the client, including the setup of an SSL VPN tunnel, some of its specific characteristics (compatibility, connection modes, etc.) and access to its logs,
- Tracking users who are connected to the SSL VPN,
- Some information regarding OpenVPN Connect.
In the rest of this document, SN SSL VPN Client may be referred to as "Stormshield SSL VPN client".
NOTE
If you are using the Stormshield VPN SSL client in version 3.x, refer to the technical note Configuring and using the SSL VPN on SNS firewalls with the SSL VPN Client v3 (PDF only).
Date | Description |
---|---|
November 13, 2024 |
|
October 7, 2024 |
|
August 22, 2024 |
|