SANGFOR IAM v2.1 User Manual
305
third party. If you want to have a third party fulfill the RADIUS authentication, correctly
configure the [Radius Server] information (including [RADIUS Server IP], [RADIUS Server Port],
[Authentication Shared Key] and [RADIUS Authentication Protocol]).
The configuration page is as shown below:
13.3.13.
Generate Certificate
The HARDCA is one of the patents of SANGFOR. The device that applies this technology can
use its certificate to get its identity authenticated among different VPN nodes. The certificate of a
device is generated with some of the features of this device and is then encrypted. Due to the
uniqueness of the device (hardware), the corresponding certificate is also unique and cannot be
counterfeited. Through this way, requiring authentication with the features of the hardware, the
IAM gateway device can ensure that only certain specified hardware device can get connected to a
network, and therefore, eliminate the potential security hazards.
Click the <Generate> button and select a path to save the generated hardware certificate to the
local computer.
Send this certificate to the administrator of the headquarters. Then, the administrator can check the
[Enable Hardware Authentication] option, upload this hardware certificate and bind the user with
this certificate while creating an account for this user.