90 Barracuda SSL VPN Administrator’s Guide
The server must be available and be populated with all users that will be used for authentication; the
appliance is merely interfacing with the results of the server and plays no part in the management of
the server content.
Once the scheme is activated all that is required is the configuration of the appliance to locate the
server. Once everything has been configured properly the user will be able to select RADIUS as the
authentication scheme to use. When the user’s authentication details are supplied, the appliance
forwards these onto the RADIUS server. The authentication result returned determines whether the
user is authenticated into the system or not.
Configuring RADIUS
The configuration parameters are vital to the success of the scheme. If any of these parameters are
incorrect, the appliance will be unable to communicate with the RADIUS server. So it is imperative
that these are understood and used correctly. The parameters are accessible from Manage System >
Advanced > Configuration > RADIUS.
OTP Authentication
OTP (One-Time-Password) Authentication can be seen as an extension to Password Authentication.
With Password Authentication the configured password is used numerous times until a defined
expiration date is hit and the password needs to be changed. The expiration tends to be around a month
or so but with OTP Authentication, the password can only be used once and once only - not only that,
the expiration of the password is measured in minutes and not days so even the OTP’s existence is
short lived.
Any email-enabled device can receive OTPs, meaning that your passwords may be sent by email to
your inbox. Alternatively, if support for SMS via email is available in the country where the
Barracuda SSL VPN resides, you can configure the OTP feature to send the password via email to an
SMS gateway which will relay the message on to the user’s cell phone.
SMS over Email
By using a third party service known as an SMTP/SMS gateway, the Barracuda SSL VPN can be
configured to relay OTPs to your users’ cell phones. This can be achieved as follows:
4.
Pick a third party SMS gateway provider in your country and sign up for their Email to SMS
service.
5.
Configure your SMTP settings in Manage System > Advanced > Configuration > SMTP and
ensure that the Barracuda SSL VPN can talk to your corporate mail server.
6.
In the same page, locate the One-Time Password section and set the Method of password
delivery to
7.
Again in the same page, locate the SMS section and enter the email address associated with the
provider of your choice in the SMS Gateway Address field.
The user will need to enter their cell phone number as a user attribute under Manage Account > My
Account > Attributes in order to receive messages via SMS.
Personal Questions Authentication
This is another commonly used Authentication Module. Its simplicity and ease of use make this a
favorite choice amongst multi-factored schemes.
Summary of Contents for SSL VPN
Page 8: ...viii Barracuda SSL VPN Administrator s Guide...
Page 34: ...34 Barracuda SSL VPN Administrator s Guide...
Page 76: ...76 Barracuda SSL VPN Administrator s Guide...
Page 94: ...94 Barracuda SSL VPN Administrator s Guide...
Page 98: ...98 Barracuda SSL VPN Administrator s Guide...
Page 104: ...104 Barracuda SSL VPN Administrator s Guide...