Whether the number of users accessible to the SSL VPN intranet server is restricted by the firewall specifications


It is not restricted by the firewall specification.

The USG controls the resources accessible to SSL VPN users. On the USG2000 or USG5000, access control policies can be configured. There are three types of access control policies: 1. Source IP address: The USG determines whether a user can access internal resources based on the source IP address. 2. Destination IP address: The USG determines whether a user can access internal resources based on the destination IP address and port. 3. Uniform resource locator (URL): The USG determines whether a user can access internal resources based on the resource URL. Access control policies can apply to users or user groups. On the USG6000, access control can be implemented based on roles. The details are as follows: 1. Service enablement: Specify services available for specified roles, including web proxy, network extension, file sharing, and port forwarding. 2. Resource authorization: Specify accessible resources if a specified service is enabled. If no resource is specified, users of the specified role cannot access any resources. After the network extension service is enabled, users can access all IP resources.

Refers to the bulk import user support for local import and server import. Local import supports CSV format files; server import supports AD server, LDAP server, and TSM server import. Import users in bulk from CSV format files 1. Select "User> Internet User> User Import". 2. Select the Local Import tab. 3. In CSV Format File Import, click CSV Template to download the CSV template to the Administrator PC. 4. Read the comment text in the CSV template carefully, fill in the user information that needs to be imported, and edit the CSV format file. 5. In CSV Format File Import, click Browse, select the pre-edited CSV format file, and click Open. 6. Select the parameters in turn. 7. Click Start Import. Import users from the authentication server on a batch basis.The device only supports bulk import of users from AD, LDAP, and TSM servers. Among them, LDAP server only supports AD and Open LDAP two types. The import type supports the following: Import only users Import only the organizational unit User and organizational unit Import only security groups Use only import security groups. After you create a new server import policy, you must perform an import policy to import users (groups) on the authentication server to the device. 1. Select "User> Internet User> User Import". 2. Select the Server Import tab. 3. Click New. 4. Select or enter the parameters in turn. 5. Click Apply. If the operation is successful, a new server import policy will be added to the Server Import Policy List. 6. In the Server Import Policy List, click the row where the policy was created. 7. In the confirmation dialog box that is displayed, click Yes to immediately execute the import policy and import the user (group) information from the corresponding authentication server.

