2.1  Accessing the web interface and user authentication

The WinRoute's web interface is available in two versions: SSL-secured or unsecured (both versions include identical pages).

Use the following address (server refers to the name or IP of the WinRoute host, 4080 represents a standard HTTP interface port) to open the unsecured version of the web interface.

https://server:4080/

To use the encrypted version specify the HTTPS protocol and number of the port of the encrypted Web interface (default is 4081):

https://server:4081/

Users logged in

User authentication is required for access to the WinRoute's web interface. Any user with their own account in WinRoute can access the web interface (regardless their access rights).

If the particular host belongs to the Windows domain, user can set to be authenticated automatically at their entrance to the web interface. If not, the firewall's authentication page is opened first waiting for a valid login username and password. The login information usually match the authentication details used for login to the user's operating system.

Login page of the firewall's Web interface

Figure 2.1. Login page of the firewall's Web interface


Warning

In network with multiple domains (typically in huge branched organizations), username with domain can be required (e.g. wsmith@us-office.company.com). To gain such information, contact your firewall's administrator.

If the user is re-directed to the page automatically (after inserting the URL of a page for which the firewall authentication is required), he/she will be re-directed to the formerly requested website after successful login attempt. Otherwise, the web interface's welcome page is displayed.

The welcome page of the web interface differs according the current user's access rights:

  • If the user is allowed to view statistics, the web interface will switch to the Kerio StaR mode and it will start with the page of overall statistics (the overall tab — for details, see chapter 3  Kerio StaR — statistics and reporting). The My Account option available at the upper-right corner can be used to switch to the user settings. It is possible to return to the statistics page by the Statistics link.

  • If the user is not allowed to view statistics, user status info page is displayed instead (see chapter 2.2  Status information and user statistics).

Log out

Once finished with activities where authentication is required, it is recommended to log out of the firewall by using the Logout button. It is important to log out especially when multiple users work at the same host. If a user doesn't log out of the firewall, their identity might be misused easily.

User can be logged on the firewall even if they have not used the web interface — e.g. if the firewall required user authentication during access to a website. To make user avoid opening the web interface when finishing their work and clicking on Logout, WinRoute includes a direct link for user logout:

http://server:4080/logout

or

https://server:4081/logout

This URL performs immediate logout of the user without the need of opening of the web interface's welcome page.

Hint

URL for user logout from the firewall can be added to the web browser's toolbar as a link. User can use this “button” for quick logout.

Note: WinRoute also allows automatic logout if idle — if the user currently logged in a session uses no Internet service for a defined time period (usually 2 hours), they are logged out of the firewall automatically. This handles situations when a user forgets to log out.

User password authentication

If an access to the web interface is attempted when an authentication from the particular host is still valid (the user has not logged out and the timeout for idleness has not expired) but the particular session [1] has already expired, WinRoute requires user authentication by password. This precaution helps avoid misuse of the user identity by another user.

Under such conditions, a special version of the login page is opened.

User authentication by password

Figure 2.2. User authentication by password


Authenticated user connecting to the web interface can continue their work in the interface after entering their password. If a new user attempts to connect to the web interface, the connected user must log out first and then the new user is asked to authenticate by username and password.



[1] Session is every single period during which a browser is running. For example, in case of Internet Explorer, Firefox and Opera, a session is terminated whenever all windows and tabs of the browser are closed, while in case of SeaMonkey, a session is not closed unless the Quick Launch program is stopped (an icon is displayed in the toolbar's notification area when the program is running).