Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","TCP Application")}}

TCP Application

{{ $t('productDocDetail.updateTime') }}: 2026-02-05

TCP application is a resource that allows end-users to use C/S-based or TCP-based applications on their local computer to access corporate resources and servers over SSL VPN.

  1. Click Add > TCP App to enter the Edit TCP Application page, as shown in the figure below:

  1. Configure the Basic Attributes of the TCP application. The following are the basic attributes:

Name/Description: Indicate the name and description of the TCP resource. This name may be seen on the Resources page after the user logs in to the SSL VPN.

Type: Indicate the type of the TCP application. Some common types are built into the Sangfor device. This selection determines the port number entered in the Port field automatically. If the TCP application is not any of the built-in types, select Other and configure the port manually.

Address: Indicate the address of the TCP resource. Click the Add icon to enter the Add/Edit Resource Address page. To add one address entry (IP address, domain name, or IP range), select the Add Address tab. To add multiple entries of addresses, select the Add Multiple Addresses tab, as shown in the figures below:

Port indicates the port used by this TCP application to provide services. For built-in types of TCP applications, this port is predefined. For Other types of TCP applications, enter the corresponding port number.

Program Path: Indicate the path of the client software program that may be used by the C/S (client/server) application.

Added To: Indicate the resource group to which this resource is added. By default, the selected resource group is the Default group (to configure the resource group, refer to the Adding/Editing Resource Group section).

Enable resource: To set the availability of this resource.

Visible for user: Selecting this option will make the resource visible to connecting users on the Resources page. Invisibility here only means that the resource is not seen on the Resources page. It is still accessible to the user.

URL Access Control: URL Access Control for HTTP resources:

Enable the URL Access Control function.

Choose the action for the access control, either allow or deny.

Add URL.

Click Instructions to display the URL access control instructions as the figure below:

 

1. The driver and plug-in for the TCP application will be installed automatically to the PC when the user logs in to SSL VPN for the first time. After that, the user must log in to Windows with an administrator account. If Windows firewall or Anti-Virus software is running, these applications must be disabled or turned off first to avoid plugin installation problems.

2. TCP application does not support file sharing type.