Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
45
Supported Two-Factor Authentication Providers
RSA
RSA is an algorithm for public-key cryptography. RSA utilizes RSA SecurID tokens to authenticate through an RSA
Authentication Manager server. RSA is not supported on all hardware platforms and is supported through RADIUS
only.
VASCO
VASCO is a public company that provides user authentication products. VASCO utilizes Digipass tokens to
authenticate through a VASCO IdentiKey server. VASCO is supported on all SMA/SRA platforms.
VASCO Data Security delivers reliable authentication through the use of One Time Password technology. VASCO
IdentiKey combined with SMA/SRA and firewall VPN appliances creates an open-market approach delivered
through VASCO IdentiKey technology.
VASCO IdentiKey allows users to utilize the VASCO DIGIPASS concept that uses One Time Passwords that are
assigned for time segments that provide easy and secure remote access. The One Time Password within the
authentication request is verified on the VASCO IdentiKey. After verification, a RADIUS access-accept message is
sent to the SMA/SRA server for authentication.
Two-Factor Authentication Login Processes
This section provides examples of the two-factor authentication login prompts when using Web login and
NetExtender.
With Web login, the
Username
and
Password
fields are used to enter the first-stage credentials.
When prompting the user to input the challenge code, the message “Please enter the M.ID PIN:” is the reply
message from the RADIUS server in this example; different RADIUS servers can have different reply message
formats.
Some RADIUS servers might require the user to respond to several challenges to complete the authentication. In
this example, the M.ID server asks the user to supply two challenges. The following passcode can be received
through email or cellphone (if SMS is configured).