thegreenbow vpn mobile - user guide

44
Property of TheGreenBow© - Sistech SA 2000-2008 TheGreenBow VPN Mobile User Guide Contact: [email protected] Website: www.thegreenbow.com

Upload: greenbow

Post on 11-Apr-2015

964 views

Category:

Documents


2 download

DESCRIPTION

Designed specifically for the mobile work force, TheGreenBow™ VPN Mobile is a software implemented VPN IPSec solution that allows a user to establish a secure connection to the corporate environment over the internet, and to have secure remote access to corporate email, files and sales application while on the road. Support 100+ VPN router see http://www.thegreenbow.com/vpn_gateway.html.

TRANSCRIPT

Page 1: TheGreenBow VPN Mobile - User Guide

Property of TheGreenBow© - Sistech SA 2000-2008

TheGreenBow VPN Mobile

User Guide

Contact: [email protected]

Website: www.thegreenbow.com

Page 2: TheGreenBow VPN Mobile - User Guide

All rights reserved. No parts of this work may be reproduced in any form or by any means - graphic, electronic, ormechanical, including photocopying, recording, taping, or information storage and retrieval systems - without thewritten permission of the publisher.

Products that are referred to in this document may be either trademarks and/or registered trademarks of therespective owners. The publisher and the author make no claim to these trademarks.

While every precaution has been taken in the preparation of this document, the publisher and the author assume noresponsibility for errors or omissions, or for damages resulting from the use of information contained in this documentor from the use of programs and source code that may accompany it. In no event shall the publisher and the author beliable for any loss of profit or any other commercial damage caused or alleged to have been caused directly orindirectly by this document.

Printed: October 2008 in San Francisco.

TheGreenBow VPN Mobile 2.0 - User Guide

Property of TheGreenBow© - Sistech SA 2000-2008

Page 3: TheGreenBow VPN Mobile - User Guide

I

TheGreenBow VPN Mobile 2.0 - User Guide

Table of Contents

Part I Introducing TheGreenBow VPN Mobile 2

................................................................................................................................... 21 What is TheGreenBow VPN Mobile ?

................................................................................................................................... 22 Multi VPN Gateway solution

................................................................................................................................... 23 Linux Appliance Support

................................................................................................................................... 24 TheGreenBow VPN Mobile Features

................................................................................................................................... 35 OEM and Software rebranding

Part II Installing TheGreenBow VPN Mobile 5

................................................................................................................................... 51 VPN Mobile Software Installation on the mobile device

................................................................................................................................... 72 VPN Mobile first launch on the mobile device

................................................................................................................................... 83 VPN Mobile Software Uninstallation

................................................................................................................................... 94 VPN Mobile Software Evaluation

................................................................................................................................... 95 VPN Mobile Software Activation

................................................................................................................................... 106 Activation Troubleshooting

Part III Quick HowTo's 12

................................................................................................................................... 121 HowTo Open VPN tunnel?

.......................................................................................................................................................... 14Tunnel Persistence

................................................................................................................................... 152 HowTo Troubleshoot VPN tunnel?

................................................................................................................................... 163 HowTo import a VPN Configuration into VPN Mobile software?

Part IV Navigating the User Interface 19

................................................................................................................................... 191 User interface elements

................................................................................................................................... 192 System Tray Icon

................................................................................................................................... 213 Portrait and Landscape modes

Part V VPN Configuration 23

................................................................................................................................... 231 Create a VPN Configuration

.......................................................................................................................................................... 23Using TheGreenBow VPN Client for laptop

.......................................................................................................................................................... 23Using TheGreenBow VPN Configurator

................................................................................................................................... 232 Upload a VPN Configuration on the mobile device

................................................................................................................................... 243 Change VPN Configuration

................................................................................................................................... 254 Import a Certificate

................................................................................................................................... 265 Using X-Auth

................................................................................................................................... 276 Default VPN Configuration

Part VI Settings 29

................................................................................................................................... 291 Protect TheGreenBow VPN Mobile Software with password

Part VII Console and Logs 33

Page 4: TheGreenBow VPN Mobile - User Guide

IITheGreenBow VPN Mobile 2.0 - User Guide

TheGreenBow VPN Mobile 2.0 - User Guide Property of TheGreenBow© - Sistech SA 2000-2008

................................................................................................................................... 331 Console Windows

Part VIII Software Localization 35

Part IX Contacts 37

Index 38

Page 5: TheGreenBow VPN Mobile - User Guide

Introducing TheGreenBow VPN Mobile

Part

I

Page 6: TheGreenBow VPN Mobile - User Guide

Introducing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

2

Property of TheGreenBow© - Sistech SA 2000-2008

1 Introducing TheGreenBow VPN Mobile

1.1 What is TheGreenBow VPN Mobile ?

TheGreenBow VPN Mobile is an IPSec VPN Client software for Windows Mobile OperatingSystem that allows to establish secure connections over the Internet usually between a remoteworker and the Corporate Intranet. TheGreenBow VPN Mobile helps IT organization to extend theIntranet to mobile workers whenever they have wireless (GSM, EGDE, 3G) or WiFi networksavailable to them. IPSec is the most secure way to connect to the enterprise as it provides stronguser authentication, strong tunnel encryption with ability to cope with existing network and firewallsettings.TheGreenBow VPN Mobile provides on Windows Mobile devices most of the features from theTheGreenBow VPN Client version for PC, making deployment of mobile workers extremely easyfor IT managers. In fact, TheGreenBow allows a quite unique capability for IT managers to use theexact same VPN Configuration on both PC and mobile version of the software.

TheGreenBow VPN Mobile is the result of many years of experience in network security andWindows network driver development, as well as extensive research in related areas.The VPN Mobile completes our range of network security products and like all our products isextremely easy to use and to install.

1.2 Multi VPN Gateway solution

TheGreenBow strategy is to support as many VPN gateway and appliance vendors as possible,available right now on the market in order to offer a true multi vendor solution to our customers.New IPSec VPN gateways or appliances are tested in our labs. The list of certified gateways isavailable on our web site and is increasing daily, thus do not hesitate to regularly check for newcertified VPN gateways.

In case your VPN Gateway is not listed, please contact our TechSupport and we'll work with you tocertified it.

1.3 Linux Appliance Support

TheGreenBow supports several implementations of Linux IPSec VPN like StrongS/WAN andFreeS/WAN. Therefore TheGreenBow VPN Mobile is compatible with most of the IPSec routers/appliances based on those Linux implementations. We will support more Linux implementations inthe future. The list of supported Linux VPN appliance is available on our website.

1.4 TheGreenBow VPN Mobile Features

Supported Windowsversions

Window Mobile 5.0 for Pocket PCWindow Mobile 5.0 for Pocket PC Phone EditionWindow Mobile 6 ClassicWindow Mobile 6 ProfessionalWindow Mobile 6.1 ClassicWindow Mobile 6.1 Professional

Supported languages English, Deutsch, Portuguese, Spanish, French.

Supported layout mode Landscape and Portrait.

Synchronization ActiveSynch4.5 (Windows XP), Windows Mobile Device Center(Vista)

Page 7: TheGreenBow VPN Mobile - User Guide

Introducing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

3

Property of TheGreenBow© - Sistech SA 2000-2008

Connection Mode Several wireless connection types like WiFi, GPRS, EDGE, 3G aresupported. A GSM/GPRS, EDGE, 3G connection is automaticallyopened if already configured and if there is no WiFi networkavailable.Allow IP Range networking.Split tunneling (forbid non-encrypted connections as soon as atunnel is opened).Tunnel persistence to maintain tunnel opened on unstable wirelessnetworks.

Tunneling Protocol Full IPSec/IKE support: Our IKE implementation is based on theOpenBSD 3.1 implementation (ISAKMPD), thus providing bestcompatibility with existing IPSec routers and gateways:

IKE aggressive mode, quick mode and main mode Tunnel mode ESP, tunnel and transport Change IKE port Mode-Config: "Mode-Config" is an Internet Key Exchange

(IKE) extension that enables the IPSec VPN gateway toprovide LAN configuration to the remote user's machine (i.e.VPN Mobile). Once the tunnel is opened with "Mode Config",the end-user is able to address all servers on the remoteLAN network by using their network name (e.g. \\myserver\marketing\budget) instead of their IP Address.

NAT Traversal NAT Traversal Draft 1 (enhanced), Draft 2 and 3 (fullimplementation)

Including NAT_OA support Including NAT keepalive Including NAT T Aggressive Mode Forced NAT-Traversal mode.

Encryption & Hash It provides AES 128/192/256 bits encryption, DES and 3-DES CBC56/168 bits.MD5-HMAC 128bits and SHA1-HMAC 160 bits.

User Authentication PreShared keying and X509 Certificates support. It iscompatible with most of the currently available IPSecgateways Flexible Certificate support (PEM, PKCS#12, ...) when

available within the VPN Configuration. Only PKCS#12Certificates can be imported directly from the mobile deviceuser interface. Support of Group 1, 2, 5 and 14 (i.e. 768, 1024, 1536 and

2048) X-Auth

Dead Peer Detection (DPD) DPD is an Internet Key Exchange (IKE) extension (i.e. RFC3706)for detecting a dead IKE peer.

Log console All phase messages are logged for testing or staging purposesallowing to easily narrow the view on specific aspects.

Same VPN Config for bothPCs and Mobile Devices

Now, IT Managers can deploy the same VPN Configuration file to allremote workers wether they have PCs or Mobile Devices such asPocket PC or Smartphones. This makes it easy to deploy largenumber of remote users.

Licensing Lifetime, Temporary, Release based Licensing are available.

1.5 OEM and Software rebranding

Our offer is specially designed to target OEM clients and System Integrators. We provide a fullyfunctional VPN Client solution to complete existing offers. Our VPN Mobile can be re-branded.

Page 8: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

Part

II

Page 9: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

5

Property of TheGreenBow© - Sistech SA 2000-2008

2 Installing TheGreenBow VPN Mobile

2.1 VPN Mobile Software Installation on the mobile device

1. Desktop to Device

TheGreenBow VPN Mobile installation is a classic Windows installation followed by asynchronization with the mobile device via one of the following software: ActiveSynch 4.5 or older on Windows XP. Windows Mobile device center on Windows Vista.

The Windows Mobile you are using must be in the OS supported list and your computer must beconnected to your mobile device. You can also look at the list of mobile devices (PocketPC,..) we,or our partners, have tested on the certified mobile devices webpage. If TheGreenBow VPN Mobileworks well with your PocketPC or SmartPhone and it is not on this list, let us know.

Launch TheGreenBow VPN Mobile on your computer, the installation will start.

Click 'Next'. The VPN Mobile software will be uploaded and installed onto the mobile device.

Page 10: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

6

Property of TheGreenBow© - Sistech SA 2000-2008

Here is what you should see on both your computer and your mobile device:On the computer using ActiveSynch.. On the Mobile Device..

Note : If the VPN Mobile software is already installed on the Mobile Device, the user is asked toconfirm the software update.

Once done, you should get a confirmation message from Windows Mobile such as:

Page 11: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

7

Property of TheGreenBow© - Sistech SA 2000-2008

Now TheGreenBow VPN Mobile is installed, click 'ok' on upper-right corner.After clicking 'ok', you'll be asked to reset the mobile device: the installation process is complete.

2. Web to Device

Not supported.

2.2 VPN Mobile first launch on the mobile device

After reset, you can start TheGreenBow VPN Mobile and an icon will appear on right end side ofthe mobile device 'Today' screen. TheGreenBow VPN Mobile is set to start when Windows Mobilestarts. This can be reversed via Window Mobile settings.

One click on the systray icon to get the menu as follow:

Page 12: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

8

Property of TheGreenBow© - Sistech SA 2000-2008

The software installation has created a new directory 'TheGreenBow' under 'My Document'containing a default VPN Configuration file i.e. 'tgbtest.tgb' that users can use to test the VPNMobile software immediately. This default VPN Configuration allows to open a tunnel with one ofTheGreenBow online VPN gateways.

To use your own VPN Configuration see section 'Upload a VPN Configuration'.

2.3 VPN Mobile Software Uninstallation

TheGreenBow VPN Mobile can be un-installed at anytime. TheGreenBow VPN Mobile un-installation is a classic Windows un-installation followed by a synchronization with the mobiledevice.

Your computer must be connected to your mobile device. Select TheGreenBow VPN Mobile un-installation in the TheGreenBow application folder on your computer. Windows Mobile DeviceCenter (Vista) or ActiveSynch (here below for Windows XP) will synchronize with your mobiledevice.

Page 13: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

9

Property of TheGreenBow© - Sistech SA 2000-2008

Uninstallation can be performed on the mobile device itself as well. Just go to Windows Mobile"Settings" then "System" then select "Remove program".

2.4 VPN Mobile Software Evaluation

It is possible to use TheGreenBow VPN Mobile during the evaluation period (i.e. limited to 30days). When the VPN Mobile is on "Evaluation" mode, the activation tab appears in the VPNMobile. Users can activate the VPN Mobile at anytime during evaluation period.

Once evaluation period expires, 'Configuration' tab, 'Settings' tab and 'Console' tab are no longeravailable and the VPN Mobile software is disabled.

2.5 VPN Mobile Software Activation

For use beyond the evaluation period, TheGreenBow VPN Mobile software must be activated. TheSoftware Activation is a simple process which requires a License Number.

Open the VPN Client software, select the 'Activation' tab and enter your Software License Numberand click on 'Activate'.

The VPN Mobile will automatically connect to TheGreenBow software activation server to activatethe VPN Mobile Software. The Software Activation process will end with a successful Activationmessage. Once the software activation is done, the 'Activation' tab disappears.

Page 14: TheGreenBow VPN Mobile - User Guide

Installing TheGreenBow VPN Mobile

TheGreenBow VPN Mobile 2.0 - User Guide

10

Property of TheGreenBow© - Sistech SA 2000-2008

2.6 Activation Troubleshooting

Errors may occurred during the activation process. Each activation error is briefly explained on theactivation window. The link "More information about this error" below the progress bar providesonline full explanations and recommendations on how to proceed next.

Most of errors encountered may be fixed by carefully checking the following points:

1. Check you entered the correct License Number (error 031).2. The communication with our activation server may be filtered by a firewall (error 053 or

error 054). Check if a personal firewall or a corporate firewall is filteringcommunications.

3. Our activation server may be temporarily unreachable. Try to activate the software a fewminutes later.

4. Your License Number is already activated (error 033). Contact our sales team:[email protected].

All activation errors are detailed online on our website: http://www.thegreenbow.com/help.html?subject=osa&id=001

Note: If you didn't succeed to activate the software despite the previousrecommendations, it is always possible to manually activate the softwareon our website: http://www.thegreenbow.com/activation/osa_manual.html.This enables users to immediately fully activate the software.

Page 15: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

Part

III

Page 16: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

12

Property of TheGreenBow© - Sistech SA 2000-2008

3 Quick HowTo's

3.1 HowTo Open VPN tunnel?

There are several ways to open a tunnel (once the VPN configuration has been imported):

1. Single click on the SystemTray icon > Click on 'Open CnxVpn1'

Once tunnel is open, the systray menu will change to allow the user to close the tunnel:

Page 17: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

13

Property of TheGreenBow© - Sistech SA 2000-2008

2. Single click on the SystemTray icon > Click on 'Configuration' > Select on 'Console' tab andclick on 'Open'.

3. Tunnel opens automatically on traffic. This feature allows the tunnel to open automatically whentraffic to the corporate network is detected. Corporate network addresses are defined in thePhase2 of the VPN configuration (i.e. 'remote LAN address). If the network is unavailable orgateway does not respond VPN Mobile tries to re-open the tunnel 4 times.

In case no connection is possible either because it has been configured or the selected wirelessnetwork is not available, the user is informed via the following popup window:

Page 18: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

14

Property of TheGreenBow© - Sistech SA 2000-2008

3.1.1 Tunnel Persistence

Wireless networks are less stable and require features to maintain the persistence of VPN tunnelsso remote users can count on stable VPN tunnels regardless. In VPN Mobile, both failures of theremote gateway and the current wireless network used can be detected to make sure the tunnel isalways on when physically possible.

1. Failure of the remote gatewayFailure of the remote gateway is detected using DPD mechanisms (Dead Peer Detection) becausethe wireless network can be available while the remote gateway has restarted its WAN interfaces.Once a failure has been detected, VPN Mobile attempts several times (i.e. configurable) to restartthe tunnel on the same network .

2. Unavailability of selected wireless networkThe selected wireless network (3G, GPRS or WiFi) is constantly monitored to detect lost. In caseof unavailability of the wireless network, VPN Mobile attempts several times to restart the tunnel onthe same network as the wireless disconnection might have been brief. If the wireless network isstill not available after several attempts, the following windows pops up to inform the user so thathe can use another wireless network depending his location:

Page 19: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

15

Property of TheGreenBow© - Sistech SA 2000-2008

3. Moving out of the office from WiFi to GSM/GPRS, EDGE or 3G wireless networkIf there is no more WiFi network available or if WiFi just failed because the user comes out of hisoffice building, a GSM/GPRS, EDGE or 3G connection is automatically opened, if alreadyconfigured/enabled, and VPN tunnel is up immediately as the VPN Mobile has detected thenetwork change instantaneously. Corporate network is still available without user noticing networkchange.

4. Moving back into the office from GSM/GPRS, EDGE or 3G wireless network to WiFiAs soon as the GSM/GPRS, EDGE or 3G connection is lost, and the WiFi connection is enabled,the VPN Mobile will try to reopen VPN tunnel immediatly without user noticing. WiFi network mightnot be available right away therefore several attempts are made till the VPN tunnel opens again.

5. Auto open tunnel on trafficIn addition, auto open tunnel on traffic feature allows to open VPN tunnel to the right gateway bydetecting traffic to that destination. In case the wireless connections have been disabled for sometimes to save battery and enabled again, VPN tunnel will open as soon as the user clik on emailsynch or tries to access an URL in the browser.

Tunnel Persistence makes easier VPN software for mobile users regardless of standards andtechnologies used by the wireless providers or the visited wireless networks.

3.2 HowTo Troubleshoot VPN tunnel?

How to troubleshoot a VPN tunnel?You will be able to find all troubleshooting issues, listed in the following documents on our website: Online help (html). Online Software Activation (html). Use the Default VPN Configuration to test you network. VPN Mobile FAQs.

Page 20: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

16

Property of TheGreenBow© - Sistech SA 2000-2008

3.3 HowTo import a VPN Configuration into VPN Mobile software?

The first step would be to upload your VPN Configuration onto the Mobile Device like any otherfiles. It is possible to use the exact same VPN Configuration file you are using with the PC versionof TheGreenBow VPN Client. However, in case several VPN tunnels have been configured in theVPN Configuration, only the first VPN tunnel configured will be uploaded into the TheGreenBowVPN Mobile.

Note: The VPN Configuration shall not protected with a password prior to import.

Step1: Single click on the SystemTray icon > click on 'Configuration' > click on 'Load'.

Step2: Select the right folder to find your VPN Configuration .

Step3: Then, double click on your VPN Configuration

Page 21: TheGreenBow VPN Mobile - User Guide

Quick HowTo's

TheGreenBow VPN Mobile 2.0 - User Guide

17

Property of TheGreenBow© - Sistech SA 2000-2008

Page 22: TheGreenBow VPN Mobile - User Guide

Navigating the User Interface

Part

IV

Page 23: TheGreenBow VPN Mobile - User Guide

Navigating the User Interface

TheGreenBow VPN Mobile 2.0 - User Guide

19

Property of TheGreenBow© - Sistech SA 2000-2008

4 Navigating the User Interface

4.1 User interface elements

TheGreenBow VPN Mobile user interface is made of several elements: Activation Tab Configuration Tab Settings Tab Console Tab System Tray Icon

4.2 System Tray Icon

The VPN Mobile user interface can be launched via a single click on application icon in systemtray. Once launched, the VPN Mobile software shows an icon in the system tray that indicateswhether a tunnel is opened or not, using color code.

VPN Mobile application color code is the following:

Page 24: TheGreenBow VPN Mobile - User Guide

Navigating the User Interface

TheGreenBow VPN Mobile 2.0 - User Guide

20

Property of TheGreenBow© - Sistech SA 2000-2008

Blue icon: no VPN tunnel is opened. Green icon: at least one VPN tunnel is opened.

Warning icon: error occurs when trying to open tunnel.

A tap on VPN Mobile icon opens the following systray menu: 'Quit' will close established VPN tunnels and quit. 'Configuration' opens the setting tabs e.g. upload VPN Configuration, change settings and

activate software. Configured tunnel with current status. Tunnel can be opened or closed from this menu as

well.

Page 25: TheGreenBow VPN Mobile - User Guide

Navigating the User Interface

TheGreenBow VPN Mobile 2.0 - User Guide

21

Property of TheGreenBow© - Sistech SA 2000-2008

4.3 Portrait and Landscape modes

Portrait and Landscape modes are both supported. However, some panels may not displayproperly when switching from one mode to another. In case mode change is required, then pleasestop and restart VPN Mobile software.

Page 26: TheGreenBow VPN Mobile - User Guide

VPN Configuration

Part

V

Page 27: TheGreenBow VPN Mobile - User Guide

VPN Configuration

TheGreenBow VPN Mobile 2.0 - User Guide

23

Property of TheGreenBow© - Sistech SA 2000-2008

5 VPN Configuration

5.1 Create a VPN Configuration

The same VPN Configuration can be deployed on TheGreenBow VPN Client for PC andTheGreenBow VPN Mobile for Windows Mobile based devices.

5.1.1 Using TheGreenBow VPN Client for laptop

IT Managers can use TheGreenBow VPN Client for PC to create VPN Configurations and importthem onto the mobile devices.

Step1: Launch TheGreenBow VPN Client for PC and open the Configuration Panel.Step2: Setup all VPN parameters, click 'Save&Apply' and export your VPN Configuration as a '.tgb'file (see also TheGreenBow VPN Client User Guide on our website)Step3: Upload your VPN Configuration on the Mobile device.

5.1.2 Using TheGreenBow VPN Configurator

In case you are not using TheGreenBow VPN Client for PC already, you can downloadTheGreenBow VPN Configurator software available on our website.

Step1: Launch TheGreenBow VPN Configurator for PC and open the Configuration Panel.Step2: Setup all VPN parameters, click 'Save&Apply' and export your VPN Configuration as a '.tgb'file (see also TheGreenBow VPN Client User Guide on our website)Step3: Upload your VPN Configuration on the Mobile device.

5.2 Upload a VPN Configuration on the mobile device

Here is how to upload your VPN Configuration onto the Mobile Device: Connect your mobile device to your PC. A new drive is created under 'My Computer', thanks to

ActiveSynch software. Drag&drop your VPN Configuration file from the computer onto the drive of the mobile device

under 'MyDocument' using Windows Explorer. From the mobile device, import the VPN Configuration into TheGreenBow VPN Mobile.

Note: It is possible to use the exact same VPN Configuration file you are using with the PC versionof TheGreenBow VPN Client. However, the VPN Client can manage only one tunnel. In caseseveral VPN tunnels have been configured in the VPN Configuration, only the first VPN tunnelconfigured will be uploaded into the TheGreenBow VPN Mobile.

Once uploaded onto the mobile device, the VPN Configuration needs to be imported inTheGreenBow VPN Mobile. Here are the steps:

Step1: Single tap on the SystemTray icon > tap on 'Configuration' > tap on 'Load'.

Page 28: TheGreenBow VPN Mobile - User Guide

VPN Configuration

TheGreenBow VPN Mobile 2.0 - User Guide

24

Property of TheGreenBow© - Sistech SA 2000-2008

Step2: Select the right folder to find your VPN Configuration and double click on your VPNConfiguration.

Step3: Then, click on 'Apply'

5.3 Change VPN Configuration

Once imported in TheGreenBow VPN Mobile the VPN Configuration can be modified.

Single click on the systray icon, and go to Configuration tab:

Page 29: TheGreenBow VPN Mobile - User Guide

VPN Configuration

TheGreenBow VPN Mobile 2.0 - User Guide

25

Property of TheGreenBow© - Sistech SA 2000-2008

Here are the settings that can be modified:

Gateway IP address or DNS address of the remote gateway (e.g. 88.162.180.79,gateway.mydomain.com).

PSK (Pre-shared key) Pre shared key as defined in the remote gateway.

Certificate X509 certificate used by the VPN Mobile . Click on 'Certificate Import ..'to select the Certificate required for user authentication.

Click on 'Apply' to make sure modifications have been taken into account.

5.4 Import a Certificate

It is possible to import a Certificate into the TheGreenBow VPN Mobile for strong userauthentication. In this software release only PKCS#12 Certificates can be imported directly fromthe mobile device.

Step1: Single click on the systray icon > go to Configuration tab > click on 'Certificate Import..' asfollowed:

Step2: Select the right folder and the required Certificate in the list:

Page 30: TheGreenBow VPN Mobile - User Guide

VPN Configuration

TheGreenBow VPN Mobile 2.0 - User Guide

26

Property of TheGreenBow© - Sistech SA 2000-2008

5.5 Using X-Auth

X-Auth is a great capability to add more security for remote users. It is possible to define the loginand password of an X-Auth IPSec negotiation. If "X-Auth popup" has been selected while buildingthe VPN Configuration, a popup window asking for a login and a password will appear each timean authentication is required to open a tunnel with the remote gateway. The end-user has fewseconds to enter its login and password before X-Auth authentication fails.

Note: This time out can be configured in the VPN Configuration but it is not taken into accountwithin the VPN Mobile.

The popup window will look like this:

In case 'Don't ask again' is selected, the login and password won't be asked each time it isrequired to open a tunnel. After the VPN Mobile restarts, the login and password for X-Authauthentication will be asked again.

Page 31: TheGreenBow VPN Mobile - User Guide

VPN Configuration

TheGreenBow VPN Mobile 2.0 - User Guide

27

Property of TheGreenBow© - Sistech SA 2000-2008

5.6 Default VPN Configuration

The VPN Mobile Setup embeds a Default VPN Configuration and this default VPN Configuration isloaded right after software installation. This Default VPN Configuration enables to open a tunnel toour TheGreenBow Demo Server.

It is particularly useful to check if a tunnel can be opened from the mobile device to an operationalremote gateway for test – and eventually for debug – purpose.

This VPN configuration file i.e. 'tgbtest.tgb' is saved in a new directory 'TheGreenBow' under 'MyDocument' created during software installation.

Page 32: TheGreenBow VPN Mobile - User Guide

Settings

Part

VI

Page 33: TheGreenBow VPN Mobile - User Guide

Settings

TheGreenBow VPN Mobile 2.0 - User Guide

29

Property of TheGreenBow© - Sistech SA 2000-2008

6 Settings

TheGreenBow VPN Mobile Settings can be defined in the 'Settings' tab:

Software Release Product Name and Software Release Number.

License Number License Number as entered during software activation.

Protected by Password If selected, password is asked when the user tries to open a tunnel,access the Configuration, Settings or Console tabs.

Block non cipheredconnection

This allow to force all traffic into the tunnel already opened. In case 'Block non ciphered connection' is not selected, the GPRS network of thewireless carrier might interpret and treat all WINS traffic depending ontheir architecture and therefore never reach your corporate network. Toavoid that, you need to force all this traffic into the tunnel so it isconveyed up to the remote LAN. It is convenient to have the ability withinthe GUI so that it can be changed depending on the network used. Plusit is a more secure way to use tunnel.

Open this application It is possible to open Outlook or any web page when a tunnel opens.Both can be selected in the same time. web pages can be defined by anURL address or an IP address.Note: URL format shall be http://www.domain.com/page.html orhttp://192.168.175.50

6.1 Protect TheGreenBow VPN Mobile Software with password

TheGreenBow VPN Mobile Software is installed WITHOUT password. Please make sure apassword is setup as soon as possible after installation.

To setup a password, click on the systray icon > go to 'Settings' tab and select 'Protected byPassword'.

Page 34: TheGreenBow VPN Mobile - User Guide

Settings

TheGreenBow VPN Mobile 2.0 - User Guide

30

Property of TheGreenBow© - Sistech SA 2000-2008

Enter your password twice for confirmation and click on 'Ok':

Password can always been changed later on by going back to 'Settings' tab. Once 'Protected byPassword' is selected, the user will be asked to enter is password whenever he tries either to opena tunnel from systray menu or to open Configuration tabs:

Page 35: TheGreenBow VPN Mobile - User Guide

Settings

TheGreenBow VPN Mobile 2.0 - User Guide

31

Property of TheGreenBow© - Sistech SA 2000-2008

Note: the password is not stored as soon as this feature is disabled, and it must re-entered againto enable the protection.

Page 36: TheGreenBow VPN Mobile - User Guide

Console and Logs

Part

VII

Page 37: TheGreenBow VPN Mobile - User Guide

Console and Logs

TheGreenBow VPN Mobile 2.0 - User Guide

33

Property of TheGreenBow© - Sistech SA 2000-2008

7 Console and Logs

7.1 Console Windows

The 'Console' tab displays the VPN IPSec messaging. This tools can be used to analyze VPNtunnel behavior which is particularly useful to IT managers in setting up their networks.

Button Description

Clear Clear console window content.

Save Save all logs in a file 'vpnlog.txt' under 'MyDocuments\TheGreenBow.

Open/Close Open or Close tunnel.

Page 38: TheGreenBow VPN Mobile - User Guide

Software Localization

Part

VIII

Page 39: TheGreenBow VPN Mobile - User Guide

Software Localization

TheGreenBow VPN Mobile 2.0 - User Guide

35

Property of TheGreenBow© - Sistech SA 2000-2008

8 Software Localization

The localization (L10N) of the VPN Mobile is now possible, even by a third party company.

Please go to www.thegreenbow.com/contribute or contact our [email protected].

Page 40: TheGreenBow VPN Mobile - User Guide

Contacts

Part

IX

Page 41: TheGreenBow VPN Mobile - User Guide

Contacts

TheGreenBow VPN Mobile 2.0 - User Guide

37

Property of TheGreenBow© - Sistech SA 2000-2008

9 Contacts

Information and update are available at: www.thegreenbow.comTechnical support by email at: [email protected] support by email at: [email protected]

Page 42: TheGreenBow VPN Mobile - User Guide

38

TheGreenBow VPN Mobile 2.0 - User Guide Property of TheGreenBow© - Sistech SA 2000-2008

Index

Index- A -Activation 9, 10

Activation errors 10

- C -Certificate 25

Certificate import 24, 25

Change a VPN Configuration 24

Change Pre-Shared key 24

Console 33

Create a VPN Configuration 23

- D -Default VPN Configuration 7, 27

- E -Evaluation period 9

- F -Feature list 2

- G -Gateway Address 24

- H -How to install ? 5, 7

HowTo create a VPN Configuration 23

HowTo import Certificates 25

HowTo open a tunnel 12

HowTo protect access with password 29

HowTo save log file 33

HowTo troubleshoot VPN 15

HowTo upload a VPN Configuration 23

- I -IKE/IPSec Logs 33

Import Certificates 25

Import VPN Configuration 16

- L -Linux appliance compatibility 2

Localization 35

Log file 33

- M -Modify a VPN Configuration 24

Multi Gateway Compatibility 2

- N -Navigating user interface 19

- O -OEM Partners 3

Open tunnel 12

- P -PKCS#12 Certificate 25

Pre-Shared key 24

Protect access with password 29

- S -Sales contact 37

Settings 29

Software Activation 9

Support contact 37

Supported Languages 2, 35

Supported Operating Systems 2

System tray icon 19

- T -Test VPN Configuration 27

TheGreenBow VPN Configurator 23

Tunnel persistence 14

- U -Uninstall 8

Upload a VPN Configuration 23

User Authentication 24, 25, 26

Page 43: TheGreenBow VPN Mobile - User Guide

Index 39

TheGreenBow VPN Mobile 2.0 - User Guide Property of TheGreenBow© - Sistech SA 2000-2008

- W -What's the TheGreenBow VPN Mobile for?

2

- X -X-Auth 26

Page 44: TheGreenBow VPN Mobile - User Guide

TheGreenBow Security Software

Secure, Strong, Simple.

Property of TheGreenBow© - Sistech SA 2000-2008