Mobile VPN for Windows Mobile Setup
WatchGuard Mobile VPN for Windows Mobile uses the data connection on a device running the Windows Mobile operating system to establish a secure VPN connection to networks protected by a Firebox or XTM device that supports Mobile VPN with IPSec. Mobile VPN for Windows Mobile has two components:
- WatchGuard Mobile VPN WM Configurator runs on a computer that can establish a connection to the Windows Mobile device using Microsoft ActiveSync. The Configurator configures and uploads the client software to the Windows Mobile device.
- The WatchGuard Mobile VPN client software runs on the Windows Mobile device. The WatchGuard Mobile VPN Service must be running in order to establish a VPN connection. WatchGuard Mobile VPN Monitor allows you to select an uploaded end-user profile and connect the VPN.
Mobile VPN for Windows Mobile uses the same .wgx end-user profile files that are used to configure Mobile VPN with IPSec. To create the end-user profile, see Configure the Firebox or XTM Device for Mobile VPN with IPSec.
Mobile VPN WM Configurator and Windows Mobile IPSec Client Requirements
Before you install the client, make sure you understand these requirements and recommendations to work with Mobile VPN with IPsec. If you have not, see the topics that describe how to configure your Firebox or XTM device to use Mobile VPN.
You must Configure the Firebox or XTM Device for Mobile VPN with IPSec. This process creates the end user profile used to configure the Windows Mobile client software.
The Mobile VPN WM Configurator system requirements are:
The Windows Mobile IPSec client device requirements are:
- Windows Mobile 5.0
- Windows Mobile 6.0
Supported devices include:
- Symbol MC70 (Windows Mobile 5 Premium Phone)
- T-Mobile Dash (Windows Mobile 6 Smartphone)
- Samsung Blackjack (Windows Mobile 5 Smartphone)
The devices in this list have been tested with WatchGuard Mobile VPN for Windows Mobile. A good way to learn if other users have successfully configured other device is to check the WatchGuard user forum, at http://forum.watchguard.com/.
To install the Windows Mobile VPN WM Configurator on some operating systems, you must log on to the computer with an account that has administrator rights and import the .wgx configuration file. Administrator rights are not required to upload the client and configuration to the Windows Mobile device.
Install the Mobile VPN WM Configurator Software
The Mobile VPN WM Configurator software must be installed on a computer that can connect to the Windows Mobile device through ActiveSync. Before you start the installation, make sure you have these installation components:
- The WatchGuard Mobile VPN WM Configurator installation file
- An end user profile, with a file extension of .wgx
- Shared Key
- A .p12 certificate file (if the VPN connects to a Firebox X Core or Peak and use certificates to authenticate)
- User name and password (if the VPN connects to a Firebox X Core or Peak and use Extended Authentication)
Write the shared key down and keep it in a secure location. You must use it when you import the end-user profile.
To install the Configurator:
- Copy the Mobile VPN WM Configurator .zip file to the computer and extract the contents of the file.
- Copy the end user profile (the .wgx file) to the root directory on the remote computer.
- Double-click the .exe file you extracted in Step 1. This starts the WatchGuard Mobile VPN WM Installation Wizard.
- Follow the steps in the wizard. In the InstallShield Wizard Complete dialog box keep the Start PDA Installation check box selected only if the Windows Mobile device is currently connected through ActiveSync.
Select a Certificate and Enter the PIN
If the VPN uses a certificate to authenticate, you must:
- Save the .p12 file to the \certs\ directory. The default location is C:\Program Files\WatchGuard\Mobile VPN WM\certs\.
- Select Start > All Programs > WatchGuard Mobile VPN > WatchGuard Mobile VPN WM to start the Configurator.
- Select Configuration > Certificates.
- On the User Certificate tab, select from PKS#12 file from the Certificate drop-down list.
- Adjacent to the PKS#12 Filename text box, type %installdir%\certs\mycert.p12. Replace mycert.p12 with the name of your .p12 file. Click OK.
- Select Connection > Enter PIN.
- Type the PIN and click OK.
The PIN is the shared key entered to encrypt the file in the Add Mobile User VPN Wizard.
Import an End-User Profile
To import a Mobile VPN configuration .wgx file:
- Select Start > All Programs > WatchGuard Mobile VPN > WatchGuard Mobile VPN WM to start the Configurator.
- Select Configuration > Profile Import.
The Profile Import Wizard starts.
- On the Select User Profile screen, browse to the location of the .wgx configuration file supplied by your network administrator. Click Next.
- On the Decrypt User Profile screen, type the shared key or passphrase supplied by your network administrator. The shared key is case-sensitive. Click Next.
- On the Overwrite or add Profile screen, you can select to overwrite a profile of the same name. This is useful if your network administrator gives you a new .wgx file and you must reimport it. Click Next.
- On the Authentication screen, you can type the user name and password that you use to authenticate the VPN tunnel. If you type your user name and password here, the Firebox or XTM device stores it and you do not have to type this information each time you connect. However, this is a security risk. You can type just your user name and keep the Password field empty. This can minimize the amount of data required for the VPN connection.
If you keep the fields empty, you must type your user name and password the first time you connect the VPN. The next time you connect, the user name field is automatically filled with the last user name entered.
- Click Next.
If the password you use is your password on an Active Directory or LDAP server and you choose to store it, the password becomes invalid when it changes on the authentication server.
- Click Finish.
Install the Windows Mobile Client Software on the Windows Mobile Device
After you import the end user profile to the Configurator, connect the Configurator to the Windows Mobile device. The computer and the Windows Mobile device must have an ActiveSync connection when you start the Configurator.
After the WatchGuard Mobile VPN software is installed on your Windows Mobile device you must reboot it.
- Connect your Windows Mobile device to your computer with Microsoft ActiveSync.
- To start the Configurator, select Start > All Programs > WatchGuard Mobile VPN > WatchGuard Mobile VPN WM.
- If the WatchGuard Mobile VPN WM software has not been installed on the Windows Mobile device, a Confirmation dialog box opens. Click Yes.
- An Information dialog box opens. Click OK.
- The WatchGuard Mobile VPN WM software is installed on the Windows Mobile device. Click OK.
- Reboot the Windows Mobile device.
Upload the End-User Profile to the Windows Mobile Device
After the Windows Mobile software is installed, you can upload the end-user profile to the Windows Mobile device.
- Connect your Windows Mobile device to your computer with Microsoft ActiveSync.
- Select Start > All Programs > WatchGuard Mobile VPN > WatchGuard Mobile VPN WM to start the Configurator.
- From the Profile drop-down list, select the profile you want to upload to the Windows Mobile device.
- Click Upload.
- When the upload is complete, the Configurator status area shows Upload completed successfully!
If the VPN uses a certificate to authenticate, you must upload the certificate to the Windows Mobile device. Before you upload the certificate, the Configurator must be set up to use the certificate.
For more information, see select a certificate and enter the PIN.
To upload a certificate:
- In the Configurator, select Configuration > Upload PKS#12 File.
- Browse to the PKS#12 file and select it. Click Open.
Connect and Disconnect the Mobile VPN for Windows Mobile Client
The WatchGuard Mobile VPN for Windows Mobile client software uses the data connection of a Windows Mobile device to make a secure connection to networks protected by a Firebox or XTM device. The Windows Mobile device must be able to make a data connection to the Internet.
- On your Windows Mobile device, select Start > Programs > WatchGuard Mobile VPN Monitor.
If the WatchGuard Mobile VPN Service is not running, a dialog box opens. Click Yes to start the service.
- The WatchGuard Mobile VPN dialog box opens. Select the end user profile from the drop-down list at the top of the WatchGuard Mobile VPN dialog box.
- Click Connect and type your user name and password. Click OK.
After the first successful VPN connection, the client saves the user name and only asks for a password. To change the user name, click OK with the password area clear. A dialog box opens in which you can enter a different user name and password.
- A yellow line with the word Connecting appears between the phone and computer in the WatchGuard Mobile VPN dialog box. The line turns green when the VPN tunnel is ready.
To disconnect the Mobile VPN client:
- On your Windows Mobile device, select Start > Programs > WatchGuard Mobile VPN Monitor.
- Click Disconnect. The green line changes to yellow.
When there is no line between the phone and computer, the VPN is disconnected.
See Also
Secure Your Windows Mobile Device with the Mobile VPN Firewall
Stop the WatchGuard Mobile VPN Service
Uninstall the Configurator, Service, and Monitor