
Related Articles
Hardware Token Authentication using SSL Client Certificates
The token or smart card contains an SSL client certificate which is used to authenticate to the system. Some vendors require software installed on
the client, or card readers depending on the solution.
SafeNet iKey 2032
Aladdin eToken PRO
Hardware Token Authentication using RADIUS Integration
Other hardware token authentication servers use a built-in or external RADIUS server. The Barracuda SSL VPN queries the RADIUS server as a
part of its multi factor authentication process. This way OTP and CryptoCard tokens can be used.
RSA SecurID
VASCO Digipass Token
Secure Computing Safeword
SafeNet iKey
This product uses a small USB device typically carried on your key chain. It uses SSL client certificates to present a certificate to the Barracuda
SSL VPN. The user also has to enter a secret pass phrase, further improving security. The client computer must have a special utility (CIP)
installed, which uploads the certificate on the USB token to the windows certificate store. The browser then uses this certificate when
authenticating to the Barracuda SSL VPN.
Aladdin eToken PRO
Similar to the SafeNet iKey the Aladdin eToken uses an SSL client certificate to authenticate. It also uses a special software, which has to be
manually installed on every client computer.
RSA SecurID
RSA SecurID uses its built-in RADIUS server to enable communication between the appliance and the RSA server. In combination with an Active
Directory user database this method is especially powerful as account management may be centrally managed with both the appliance and RSA
Authentication Manager reading accounts from your Active Directory domain.
VASCO Digipass
A VASCO server can authenticate with the Barracuda SSL VPN via an external RADIUS server. The VASCO server currently does not include a
RADIUS server.
Secure Computing Safeword
Safeword servers include a RADIUS feature that can be used to authenticate to the Barracuda SSL VPN. Note that Safeword requires an Active
Directory database and Internet Authentication Server (IAS) installed on the Domain Controller.
How to Configure One-Time Password (OTP) Authentication
One-time passwords (OTPs) are passwords that can only be used once in a predefined
time frame, usually just minutes. You can configure the Barracuda SSL VPN to send
the OTP to users by either email or SMS. OTPs do not require any special hardware or
infrastructure. Any device that receives email or SMS can be used to receive the OTP.
To configure the Barracuda SSL VPN to send OTPs by email, configure the
SMTP server and the OTP settings.
To configure the Barracuda SSL VPN to send the OTPs by SMS, configure the
SMTP server, the OTP settings, and an SMTP to SMS service.