Authentication Schemes 89
3.
Now when the user next logs into the system they will be presented with the first authentication
method and if successful, the second authentication method (Authentication Key) will not ask
for a key but rather force the user to generate a new one
Much like before the identity will need to be safely stored on a secure medium such as a USB key.
The user will be logged into the system and will now posses a new identity which will need to be
presented the next time they log in..
Configuring Public Key
The Public Key configuration page can be accessed from Manage System > Advanced >
Configuration > Key Authentication.
• Allow User to Create Initial Authentication Key: The administrator has the option of
creating keys for the entire user base from the Edit Accounts page; this option however
alleviates this need by forcing the users themselves to create their own key files at login
time. If the user chooses key authentication the system will force the creation of a key.
• Enforce Password Security Policy: Enforce that passphrase conforms to the password
policy under Manage System > Advanced > Configuration > Password Options.
Import Authentication Key
This function allows for an already existing public key to be imported into the Barracuda SSL VPN
as a user Authentication Key. This action can be performed by any users who have account editing
privileges.
When the appliance scans a device such as a USB key, it tries to find the Authentication Key. This
key should be in the root directory of the device in a sub-folder called “.sslvpn-ids”. So in order for
the external device to operate as required the public key file must always be in this folder for example,
E:\.sslvpn-ids\myPublicKey.pub.
1.
From the Accounts page (Manage System > Access Control > Accounts) click the More…
button against the user you wish to reset an identity for. From the action list select the select the
Import Authentication Key action.
2.
Simply locate the *.pub file that you wish to import using the file system Browse button.
3.
Once the file is chosen simply use the Upload button to import the Authentication Key.
RADIUS Authentication
The RADIUS Authentication method (Remote Authentication Dial In User Service) is known as an
AAA (authentication, authorization and accounting) protocol. It allows for a RADIUS server to be
queried by the appliance in order to validate a user’s login request.
As the RADIUS server is outside of the control of the appliance, certain actions will not be available
such as ‘create’ or ‘edit’. This also has an effect on how this module is used in an authentication
scheme. As a username and password are supplied it can be used as either a primary or secondary form
of authentication. It can also be combined with other modules, but of course care should be taken to
ensure that the selected modules within an authentication scheme are compatible.
The prerequisite for this authentication method is:
• Operating RADIUS server
Summary of Contents for SSL VPN
Page 8: ...viii Barracuda SSL VPN Administrator s Guide...
Page 34: ...34 Barracuda SSL VPN Administrator s Guide...
Page 76: ...76 Barracuda SSL VPN Administrator s Guide...
Page 94: ...94 Barracuda SSL VPN Administrator s Guide...
Page 98: ...98 Barracuda SSL VPN Administrator s Guide...
Page 104: ...104 Barracuda SSL VPN Administrator s Guide...