38.15 Usage Example

Enterprise Setup:

  • 1. All internal network servers (e.g., SVN server, JIRA server, VoIP server, etc.) are deployed in Subnet 1.
  • 2. The access gateway is connected to the network in a serial configuration, with an IP address of 192.168.2.1. All machines from non-Subnet 1 will pass through the access gateway when accessing the internal network servers.

Requirements to Implement:

  • 1. Employees' computers need to have the AnySecura client installed and be running the company’s internal communication tool RTX to access internal network servers.
  • 2. Network printers and IP phones should function normally.
  • 3. For certain executives, these restrictions are not necessary.
  • 4. For occasional partners visiting the company for communication, their computers are not suitable for installing the AnySecura client. When these partners connect to the company’s wireless network, they will use IP addresses in the range of 192.168.3.1-192.168.3.20.

For the above requirements, the following settings can be made:

Settings on the Access Gateway:

  • ① Access Gateway Configuration -> Control Range: Set the control range to include all company network addresses except for the 1 subnet.
  • ② Access Gateway Configuration -> Exception Rules: Add the IP addresses of the network printers and IP phones.
  • ③ Access Gateway Configuration -> Warning Page: Choose the system warning page and modify the page content as needed.
  • ④ Access Gateway Configuration -> Whitelist: Add the IP addresses of the executives' machines that do not require restrictions.
  • ⑤ Visitor Login Management -> Visitor Management: Add visitors, set the account name, password, and comments, then in the login settings, check "Only allow login from specified IP addresses" and enter the specified IP range: 192.168.3.1-192.168.3.20.

Settings on the AnySecura Console:

  • ① Tools -> Access Gateway Management: Add the Access Gateway with the IP 192.168.2.1.
  • ② Security Detection -> Security Detection Conditions: Add a new security detection condition:
    • Enter the condition name, such as "RTX Installation".
    • In the security detection condition settings window, select the "Program Check" tab, check "All of the following programs must be running", and add the process RTX.exe.
  • ③ For all clients, Security Detection -> Security Detection Settings: Add a policy:
    • Choose the previously added RTX Installation security condition.
    • In the policy attributes on the right, check "Block Access".

After completing these settings, enable the Access Gateway control function.