User Interface
R&S
®
GP-U/GP-E/GP-S/GP-T
32
User Manual 3646.3836.02 ─ 01
8. Click "Login".
The authentication is carried out.
For security reasons, it is strongly recommended to update the UA client to the latest
version available. However, a compatibility mode that allows older versions of the UA
client to work with the gateprotect Firewall version 10 can be enabled. For more infor-
mation, see
"User Authentication / Directory Service Settings"
Logging on via Single Sign-On (SSO)
When using Single Sign-On (SSO), domain users from the Active Directory domain log
on to a Windows client. Firewall rules configured on the gateprotect Firewall concern-
ing these users are then automatically applied.
To realize SSO with the gateprotect Firewall in an Active Directory environment, the
following preconditions have to be met:
1. As Kerberos is time-critical, make sure to set the same time/NTP server for all
components of SSO (domain controller, Windows client and gateprotect Firewall).
2. Creating the user
gpLogin
It is necessary to create a normal domain user in the user management under
"CN=Users" in the Active Directory. This user is then assigned a so-called Service
Principal Name (SPN) which is needed for the authentication of the gateprotect
Firewall on the server. The user does not need any specific rights.
a) Open the domain controller.
Figure 3-6: Creating a new user – user logon name.
Menu Reference