. . . . .
S E C U R I T Y Z O N E S A N D I N T E R F A C E S
Authentication Using RADIUS
Version 3R2
Security Appliance User Guide
3-27
completion of user authentication. The following example illustrates the
Challenge-Response authentication mode with RADIUS (
Figure 3-11
).
Figure 3-11: RADIUS Challenge Response Message Exchange
1
User tries to establish a VPN Tunnel with the security appliance
2
The security appliance prompts the remote user for a username and password.
3
User provides his username and password to the security appliance.
4
The security appliance queries the RADIUS server to verify the authentication.
5
The RADIUS server verifies the username and password and if they are correct,
sends a RADIUS Challenge message to the security appliance.
6
The security appliance sends the Challenge message to the user.
7
User responds to the Challenge question by entering other information (in this
example a Pin code).
8
The RADIUS server can be used to authenticate the pin code itself, or optionally
use a 3
rd
party authentication server to authenticate the pin code. In this example
there is a 3
rd
party server, and the RADIUS server connects to the 3
rd
party to verify
the pin code.
9
The 3
rd
party server verifies the pin code and gives verification response.
10
The RADIUS server sends RADIUS Response to the security appliance.
11
The security appliance sends XAUTH response to User VPN Client.