Defining Prelogin Policies
In the supported Windows, OS X, and Linux-based operating systems, you can define the potential locations where the client computers might be connecting from. For example, if your users connect from the office network, home office network, and even Internet cafés, you can define a location for each setup and give appropriate access to your users. For users connecting from the office network, you classify those hosts fairly securely and allow a less restrictive environment. For users connecting from their home office, you can classify them as somewhat secure and apply more restrictive policies. For users connecting from Internet cafés, you classify them as least secure and apply the most restrictive policies.
Throughout this chapter, we use three prelogin locations to build configurations. They include
• OfficeCorpOwned: This location is defined for those workstations that establish an SSL VPN tunnel from the corporate-owned IP addresses. Additionally, the workstation must have a unique registry setting to identify it as a corporate-owned computer. If workstations match this profile, Secure Desktop or Cache Cleaner will not be launched.
• HomeCorpOwned: This location is defined for those Windows computers that are corporate-owned but are employed by users who establish an SSL VPN tunnel from their home offices; these addresses do not match the corporate-owned address range. The workstations are classified as corporate owned by identifying a unique registry setting. If workstations match this profile, Secure Desktop will be launched.
• InternetCafé: This location is defined for those computers that do not match any of the previous profiles. Cache Cleaner will be launched.
These profiles are defined by choosing Configuration > Remote Access VPN > Secure Desktop Manager > Prelogin Policy. You can define prelogin locations by having the workstations meet a number of criteria. CSD supports the following five ways to identify a host:
• Certificates: If your client workstations use unique computers, you can use the subject and the issuer names to match a specific profile. The subject and issuer names contain a number of subordinate fields such as common name (CN), organization (O), organizational unit (OU), and country , to name a few. You can use one of the subordinate fields in the subject and issuer names to identify computers that match a specific profile.
NOTE To identify computers based on certificates, specify the values of the subordinate fields. For example, to identify computers based on organizational unit (OU), simply specify the value of OU but do not list OU in the names.
• IP address range: If you know the IP address space of client computers, use this feature to identify computers that match a profile. You can define one or multiple address spaces to identify computers.
NOTE If the client computer has multiple IP addresses, CSD uses the first identified IP address to match against a profile.
• File setting: You can use the location of a file to identify computers. This feature is useful if, for example, you want to identify a specific file to determine whether computers are corporate owned.
• Registry setting: You can use a registry key to identify computers. This feature is useful if you want identify a specific registry location to determine whether computers are corporate owned. A registry check is applicable only for Windows-based operating systems.
• Operating system version: The host assessment provides the version of operating systems running on the remote workstation. The operating system check is for Windows 9x, 2000, XP, Vista, Mac OS X, and Linux. Secure Desktop is allowed only for Windows Vista (32-bit), XP and 2000 operating systems. For other operating systems, Cache Cleaner is supported.
NOTE
If you specify more than one registry key or file location, CSD applies an OR logical operation. For example, if you define the location of a registry key and define the location of a file, one of the locations must be present to identify a host.
To configure a prelogin location, choose Configuration > Remote Access VPN > Secure Desktop Manager > Prelogin Policy and select the appropriate check from the drop-down menu. As illustrated in Figure 5-47, a registry check is being done. If HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VirusScan exists, CSD continues on and performs other checks. If a workstation does not have this registry key, it is classified as InternetCafe.
Figure 5-47 Defining a Registry Check
Figure 5-47 Defining a Registry Check
The workstations that have the registry setting are further accessed for additional checks. In Figure 5-48, workstations are checked for their IP addresses. If they are in the 192.168.1.0/24 subnet, they are identified as OfficeCorpOwned workstations. If they are not, they are identified as HomeCorpOwned workstations.
Figure 5-48 Defining an IP Range Check
Figure 5-48 Defining an IP Range Check
NOTE If you want to identify a computer by locating a specific file in the system and ensuring the integrity of the file, you can find its checksum. To assist you with calculating the correct checksum of a file, CSD provides the crc32.exe application.
Continue reading here: Setting Up Basic Host Scan
Was this article helpful?