84 Barracuda SSL VPN Administrator’s Guide
Authentication Schemes
An Authentication Scheme is simply a container for any number of Authentication Modules, such as
OTP, Passwords, and Certificates. This approach means that multi-tiered authentication can easily be
implemented and even linked to existing authentication systems. The Authentication Scheme is then
used as the basis of the login policy. The Barracuda SSL VPN allows for more than one of these
schemes to be created and used.
All Authentication Schemes defined are visible from Manage System > Access Control >
Authentication Schemes, and are listed in order of priority.
The following types of authentication can be used to control the level of access to a module:
The above table also shows where an Authentication Module can be placed in relation to other
modules. Any module marked above with primary means that it can be positioned first in an
Authentication Scheme whilst any module defined as secondary cannot be first in a scheme. Most of
the Authentication Modules can be positioned anywhere first or second. Within the application itself,
only those that cannot be first are marked.
The Authentication Scheme system enforces this by disallowing a secondary scheme to be positioned
at the top of the chain. It is important to note that certain Authentication Modules can only be used
by themselves; that is they cannot be combined with other Authentication Modules.
When a user starts the authentication process they first have to enter a Username. Once the Username
is submitted, checks are made to determine the correct authentication method to be used. This
approach allows for different authentication methods to be used for different groups of users. For
example, users attached to a Sales Policy may only have to enter a Username and Password, whereas
Sales Management may be attached to a Policy that uses a Password and PIN authentication scheme.
Note: If only one Authentication Scheme is configured on the system and only one User Database is
configured, then users will be prompted for their username and password on the same screen. If more
than one Authentication Scheme is configured they will be prompted for username (and User
Database if more than one is in use). Once accepted another page will prompt for the password.
The built in authentication schemes allow those wanting to build a single, double or even a triple
factored process to do so with ease. So, if only the default Authentication Scheme has been defined,
the Login page presented to the user will have:
• Language selection
• Username entry
Authentication
Type
For More Information:
Client Certificate
Primary/Secondary
page 85
IP Address
Primary/Secondary
page 86
Password
Primary/Secondary
page 86
PIN
Primary/Secondary
page 87
Public Key
Primary/Secondary
page 87
RADIUS
Primary/Secondary
page 89
OTP (One-Time Password)
Secondary
page 90
Personal Questions
Secondary
page 90
Summary of Contents for SSL VPN
Page 8: ...viii Barracuda SSL VPN Administrator s Guide...
Page 34: ...34 Barracuda SSL VPN Administrator s Guide...
Page 76: ...76 Barracuda SSL VPN Administrator s Guide...
Page 94: ...94 Barracuda SSL VPN Administrator s Guide...
Page 98: ...98 Barracuda SSL VPN Administrator s Guide...
Page 104: ...104 Barracuda SSL VPN Administrator s Guide...