Create mobile users and their membership group for the IPsec VPN

The suggested method consists of creating a group that contains all the mobile users allowed to set up IPsec VPN tunnels, then assigning the appropriate privilege to this group.

This section assumes that the LDAP directory containing the users is configured and operational. If you need to create an internal LDAP directory on the firewall, refer to the section Creating an internal LDAP in the SNS v5 User Manual.

NOTE
If you are using an external directory, users must have been created there beforehand and this directory must be defined on the SNS firewall.
In this case, go directly to the Creating a group that contains all the users allowed to set up IPsec VPN tunnels.

Create a mobile user in the firewall’s internal directory

Go to to Configuration > Users > Users and Groups:

  1. Click Add user and select the directory to which you want to add the user. In this example: internal LDAP directory corresponding to the stormshield.eu domain.
  2. In the ID (login), enter the user’s login in the form firstname.lastname. In this example: john.doe..
  3. Enter the user's Name. In this example: eaptls.
  4. Enter the user’s First name.  In this example: user1.
  5. Enter the user's Email address. In this example: john.doe@stormshield.eu..
  6. Enter and confirm a User password.
  7. Click on Next then on Finish.

Create the other mobile users to connect to the IPsec VPN by following steps 1–7 again.

Creating a group that contains all the users allowed to set up IPsec VPN tunnels

NOTE
For an external directory, such groups must be created directly on one of the workstations that hosts the directory.

Create the group and associate an initial member with it

Go to to Configuration > Users > Users and Groups:

  1. Click Add group and select the directory in which this group will be created. In this example: internal LDAP directory corresponding to the stormshield.eu domain.
  2. In the Group name field, enter a representative name. In this example: EAP-TLS VPN Users.
    You can add a Description.
  3. In the Initial member field, select the previously created user. In this example: john.doe@stormshield.eu.@stormshield.eu.
  4. Click on Create.

Adding users to the group authorized to set up an IPsec VPN tunnel

Go to to Configuration > Users > Users and Groups:

  1. On the left side of the screen, select the group. In this example: EAP-TLS VPN Users.
    The properties of the group and the list of its members are displayed on the right-hand side of the screen.
  2. In the List of group members, click on Add.
  3. Select the desired user and click Apply.
  4. Once all users have been added to the group, click the Apply button at the bottom of the group properties.