259
Limiting user access
Authenticating with an external authentication server
Installing RSA SecurID software
You must install RSA SecurID/Server software a host on the inside (protected) network. After you
install the software, you must configure it.
Prerequisites
None.
To install RSA SecurID software
1
Install the RSA SecurID/Server software on a host on the inside (protected) network, as described
in the RSA SecurID/Server documentation.
Be sure that the host name of the RSA SecurID/Server resolves to the correct IP address. Problems
with name resolution will prevent RSA SecurID authentication from working.
2
On the RSA SecurID/Server, define the security gateway as the RSA SecurID/Client. If your version
of the RSA SecurID/Server wants to know what type of client the security gateway is, click
communications server
.
3
Import tokens, assign users to tokens, and activate tokens for use on the SecurID Client as
described in the RSA SecurID documentation.
4
Set the time zone, date, and time on the RSA SecurID/Server. Set the time zone, date, and time on
the security gateway. Make sure to synchronize the system time with the RSA SecurID server time
or synchronize them both to a common source.
5
Optionally, perform the RSA SecurID/Client installation on the system with the clntchk applet.
Ensure that the host name and address of the master RSA SecurID/Server are correct.
6
Test the RSA SecurID authentication mechanism with the RSA SecurID/Client applet (Start >
Settings > Control Panel > SecurID > Client).
Testing authentication downloads the node secret, making this secret unavailable to the security
gateway. This must be corrected after testing by using the RSA SecurID Server administration
applet to reset the node secret for the client. This is done by selecting edit client from the client
drop-down menu, selecting the system, and then unchecking the sent node secret check box (leave
the box checked for Solaris).
Related information
For further information related to this topic, see the following:
■
“SecurID Properties—General tab”
Configuring RSA SecurID authentication
Similar to the other external authentication server types, you have to configure an RSA SecurID
authentication server record for your external authentication method.
Prerequisites
None.
To configure a new RSA SecurID authentication server record
1
In the SGMI, in the left pane, under Assets, click
Authentication Servers
.
2
In the right pane, on the Authentication Servers tab, click
New > SecurID
.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...