18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Supported<br />

authentication<br />

methods<br />

Supported authentication methods<br />

<strong>Sidewinder</strong> <strong>G2</strong> supports standard UNIX password authentication,<br />

Windows Domain authentication, and the following stronger<br />

authentication methods: SafeWord PremierAccess and SafeWord<br />

RemoteAccess (from Secure Computing Corporation), SecureNet<br />

Key (SNK) from Symantec Corporation, and SecurID from RSA<br />

Security, Inc. <strong>Sidewinder</strong> <strong>G2</strong> also supports the widely-used RADIUS<br />

authentication protocol and the Lightweight Directory Access Protocol<br />

(LDAP). All <strong>of</strong> these can be used to authenticate SOCKS5, Telnet, FTP,<br />

and Web connections through the <strong>Sidewinder</strong> <strong>G2</strong> and administrator<br />

log in connections to the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

Note: Single Sign-On (SSO) can be used in conjunction with the authentication methods<br />

listed below to cache a user’s initial authentication, thereby allowing access to multiple<br />

services with a single authentication to the <strong>Sidewinder</strong> <strong>G2</strong>. For information on configuring<br />

SSO, see “Configuring SSO” on page 9-27.<br />

Table 9-1. Authentication methods available for the <strong>Sidewinder</strong> <strong>G2</strong><br />

Authenticatio<br />

n Method<br />

Standard<br />

Password<br />

SafeWord<br />

(PremierAccess<br />

and<br />

RemoteAccess)<br />

Security<br />

Level<br />

Recommended<br />

Usage<br />

Weak Internal-to-external login, FTP,<br />

Telnet, Web, SOCKS5, or SSH<br />

sessions<br />

Strong External-to-internal login, FTP,<br />

Telnet, Web, SOCKS5, or SSH<br />

sessions<br />

LDAP Weak Internal-to-external login, FTP,<br />

Telnet, Web, SOCKS5, or SSH<br />

sessions<br />

Windows<br />

Domain<br />

SecureNet Key<br />

(SNK)<br />

Weak Internal-to-external login, FTP,<br />

Telnet, Web, SOCKS5, or SSH<br />

sessions<br />

Strong External-to-internal login, FTP,<br />

Telnet, or SSH sessions<br />

SecurID Strong External-to-internal login, FTP,<br />

Telnet, Web, SOCKS5, or SSH<br />

sessions<br />

RADIUS Strong External-to-internal login, FTP,<br />

Telnet, Web, or SSH sessions<br />

Server<br />

Type<br />

Authenticator<br />

Type<br />

Not applicable Not applicable<br />

SafeWord Authentication<br />

Server, external to the<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

X.500 directory server,<br />

external to the<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

Windows primary<br />

domain controller (PDC)<br />

or backup domain<br />

controller (BDC)<br />

Defender Security Server<br />

(DSS), external to the<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

ACE/Server, external to<br />

the <strong>Sidewinder</strong> <strong>G2</strong><br />

RADIUS server, external to<br />

the <strong>Sidewinder</strong> <strong>G2</strong><br />

S<strong>of</strong>tware (S<strong>of</strong>tToken<br />

II) and hardware token<br />

(Silver 2000, Gold 3000,<br />

Platinum)<br />

Not applicable<br />

Not applicable<br />

SecureNet Key (SNK) or<br />

Symantec Corporation<br />

hardware<br />

authenticator<br />

SecurID hardware<br />

authenticator<br />

Any<br />

Setting Up Authentication 9-5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!