Appendix B: Modifying the default AVG for SSL VPN (with screens)

Last Updated : Dec 17, 2015 |
After running the Quick Setup and Net Direct configuration wizards, the default configuration must be modified to support an SSL VPN connection with an IP Office system.
Perform this procedure using the AVG browser-based interface (BBI). See Avaya VPN Gateway BBI Application Guide.
Prolog information
Before you begin
Ensure that the default gateway configuring on AVG responds to ICMP requests. If the default gateway does not respond to ICMP requests, the AVG cannot provide VPN services.
  1. Log on to the AVG BBI as administrator.
  2. In the navigation pane on the left, select the Config tab and then VPN Gateway VPN1 IP Pool.
  3. The default VPN from the basic AVG configuration may already have a local pool. If not, you must add a local pool to the default VPN. On the Add new IP Address Pool page, add a local pool to the default VPN.
    ADDITIONAL INFORMATION:
  4. On the Modify IP Address Pool page, verify that the values in the Lower IP and Upper IP fields match values set using the Net Direct Configuration wizard.
    ADDITIONAL INFORMATION:
  5. On the IP Pool Network Attributes Settings page, select the Network Attributes tab and enter the values for your network.
    ADDITIONAL INFORMATION:
  6. On the IP Pool page, set the Default IP Pool to the local poll created in step 3.
    ADDITIONAL INFORMATION:
  7. On the Net Direct Client Access Settings page, verify the settings created by the Net Direct Configuration wizard.
    1. Ensure that Idle Check is set to off.
      ADDITIONAL INFORMATION:
    2. Ensure that the Net Direct Banner is set.
      ADDITIONAL INFORMATION:
  8. Set the portal link for launching the Net Direct client. On the Portal Linkset Configuration page, Select the Portal Link tab. In the Link Type field, select Net Direct.
    ADDITIONAL INFORMATION:
  9. On the Networks for Split Tunnels page:
    1. Set Split Tunnel Mode to enabled.
      ADDITIONAL INFORMATION:
    2. Set the split tunneling routes to reach the service agent on the private network.
      ADDITIONAL INFORMATION:
  10. For VPN1, go to the groups page and select Group1. On the Modify a Group page, set the IP Pool to the local pool created in step 3.
    ADDITIONAL INFORMATION:
  11. Go to the VPN1 Group1 Access Lists page. On the Firewall Access List page, create an access rule if it was not created by default.
    ADDITIONAL INFORMATION:
  12. Go to the VPN1 SSL page. On the Server Settings page, under SSL Settings set Ciphers to AES256-SHA for a strong encryption.
    ADDITIONAL INFORMATION:
  13. Go to the VPN1 AuthorizationServices page. Remove all the services set in the default configuration as they are not required by SSL VPN.
    ADDITIONAL INFORMATION:
  14. Go to the VPN1 AuthorizationNetworks page. Set the authorization network subnet that is referenced in one of the access rules that is set under VPN1 Group1 Access Lists.
    ADDITIONAL INFORMATION:
    Note:
    This setting controls SSL VPN tunnel inter-communication. Communication is only enabled by specifying an “intranet” networks allowed list. Inter-VPN client communication is blocked by default.
  15. Go to the VPN1 General SettingsSession page. Set Session Idle Time to 2 minutes.
    ADDITIONAL INFORMATION: