Setting Up FirePass Server Security
FirePass
™
Server Administrator Guide
3 - 25
10. Click the Save Settings button.
To test the RADIUS authentication settings
1. Click the Test button.
2. Enter a user name and password in the RADIUS server, and then
click the Test button.
Setting up a RADIUS server to work with the FirePass server
To use SecurID, make sure that the SecurID Radius service is running. The
FirePass server does not authenticate to the native SecurID protocol.
Even if the RADIUS service has been started from the SecurID options
window on an NT SecurID server, the service may not be active. In the
Windows Services Manager, make sure that the service is set to start each
time the server boots and is currently running. The RADIUS authentication
takes place on a different port than native SecurID authentication.
On the RADIUS server, the FirePass server needs to be set up as a client to
the RADIUS server. Then, a shared secret needs to be created and added to
both the RADIUS server and the FirePass server so the RADIUS server can
trust the FirePass server.
On all Secure ID servers, the SecurID server needs to be made a client of
itself to make the RADIUS server function. The RADIUS service functions
as a standalone process and if the SecurID server is not set up as a client of
itself, it rejects the authentication request and not store anything in the logs,
making this problem difficult at best to diagnose. The FirePass server
merely reports that the authentication has failed.
Note
The FirePass server uses the Radius protocol when communicating with the
RSA Radius or ACE server. If you are using a RSA ACE server, you must
add support for the Radius protocol in order for the FirePass server to
communicate with it. You can do this by adding a “Radius Agent Host” to
the RSA server configuration. For more information, see the documentation
for your RSA server.
Setting up Windows domain server authentication
If the Windows Domain authentication feature is licensed, you can use
Windows Domain authentication to authenticate users against an internal
Windows NT/2000/2003 based server. The following two authentication
modes are supported:
◆
Native NTLM authentication
Native NTLM authentication is supported if you specify domain
administrative credentials when you set up Windows Domain
Содержание FirePass
Страница 1: ...FirePassTM Server Administrator Guide version 4 0 MAN 0081 00 ...
Страница 2: ......
Страница 4: ...ii ...
Страница 5: ...Table of Contents ...
Страница 6: ......
Страница 12: ......
Страница 18: ...Chapter 1 1 6 ...
Страница 20: ......
Страница 44: ...Chapter 2 2 24 ...
Страница 46: ......
Страница 82: ...Chapter 3 3 36 ...
Страница 84: ......
Страница 124: ......
Страница 156: ...Chapter 5 5 32 ...
Страница 158: ......
Страница 168: ......
Страница 177: ...Index ...
Страница 178: ......