265
Limiting user access
Authenticating using Out-Of-Band Authentication (OOBA)
contains a list of supported authentication servers (or conditionally supported) on the
security gateway if you are not using the OOBA authentication capability. To authenticate any proxies
that are not listed in the supported types list,
or to authenticate those listed in the table
unconditionally, you must use OOBA using the OOBA daemon listed among the
services in the SGMI.
The security gateway includes the necessary HTML pages that prompt users for their user names and
passwords when they try to access the system. Depending upon the authentication scheme they are
using, along with OOBA and the proxy in use, the system continues to prompt the user for data until
the correct authentication scheme and password are returned.
Configuring the OOBA service
To authenticate users with OOBA, you must configure the OOBA service on the security gateway. After
you configure OOBA, you can enable OOBA authentication in a rule.
Prerequisites
None.
To configure OOBA authentication
1
In the SGMI, in the left pane, under System, click
Configuration
.
2
In the right pane, on the Services tab, select OOBA Daemon, and then click
Properties
.
3
In the Service Parameters for OOBA Properties dialog box, on the General tab, do the following:
4
On the Timeout tab, do the following:
Table 7-2
Supported authentication servers
Authentication server
HTTP
FTP
NNTP
Telnet
Client VPN
Internal authentication
Yes
Yes
Yes
Yes
Yes
Microsoft Active Directory
Yes
Yes
Yes
Yes
Yes
LDAP(S)
Yes
Yes
Yes
Yes
Yes
RADIUS
Yes
Yes
Yes
2
Yes
Yes
RSA SecurID
Yes
Yes
Yes
Yes
Yes
1 Supported in Event Synchronous Mode only
2 Supported only if not a challenge/response password mechanism
Enable
To enable the OOBA daemon, check
Enable
.
Authentication scheme Select the authentication scheme that OOBA should use to authenticate users.
Caption
Type a brief description of the OOBA daemon.
Inactivity Timeout
Use the arrow buttons to select the timeout intervals in seconds.
This value determines how long an idle OOBA connection can remain open. The default
is 3600 seconds (one hour) for HTTP and other connections.
Maximum Lifetime
Use the arrow buttons to select the maximum session intervals in seconds.
Maximum Sessions
Use the arrow buttons to select the maximum number of sessions.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...