
244
Limiting user access
Configuring users for internal authentication
You can use user accounts in rules, VPN tunnels, and clientless VPN roles to control authentication.
You can also combined individual user accounts in user groups.
You can create user accounts on the security gateway’s internal server, or on external authentication
servers that are supported on the security gateway. For instructions on creating user accounts on an
external authentication server such as LDAP, see the documentation for that server.
For instructions on creating a user on the security gateway’s internal authentication server, see the
following:
■
“Creating a user account on the internal server”
■
“Creating an IKE-enabled user”
■
“Ensuring that the internal server is enabled”
Creating a user account on the internal server
The security gateway includes an internal authentication server that uses information contained in a
local database of users and groups to grant access. The primary purpose of the internal authentication
server is to let you configure and control access for defined users and groups, without an external
authentication server. The internal authentication server replaces two older methods of
authentication, Bellcore S/Key and gwpasswd, which are no longer supported.
The security gateway’s internal authentication server stores the following information for each user:
Note:
With the 3.0 release, Bellcore S/Key and gwpassword are no longer supported authentication
schemes. If you have upgraded from Symantec Gateway Security v2.0, see the upgrade section of the
Symantec Gateway Security 5000 Series v3.0 Installation Guide
for instructions.
Prerequisites
None.
To create a user account on the internal server
1
In the SGMI, in the left pane, under Assets, click
Users
.
2
In the right pane, on the Network Users tab, click
New
.
3
In the New User Account properties dialog box, on the General tab, do the following:
User name
Unique user name for this user.
Password
Used to authenticate the user name.
First (given) name
User’s first name.
Last (family) name
User’s last name.
Full name
User’s full name.
Groups
One or more groups of which this user is a member.
ID
Unique user ID. This is normally generated by the security gateway when the user is first
created.
Password dates
Applicable password dates (expiration, warning, minimum duration, maximum duration).
Enable
To enable the user, check
Enable
.
User name
Type a unique name for the user.
First name
Type the first name of the user.
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...