18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Supported authentication methods<br />

When connected to the <strong>Sidewinder</strong> <strong>G2</strong> using standard RADIUS ports,<br />

the authentication method is appropriately called RADIUS. This<br />

method is available with both SafeWord RemoteAccess and SafeWord<br />

PremierAccess. (For additional information on RADIUS, see “RADIUS<br />

authentication” on page 9-8.)<br />

SafeWord PremierAccess provides the ability to use fixed passwords<br />

or passcode authentication for Telnet and FTP sessions through the<br />

<strong>Sidewinder</strong> <strong>G2</strong>, and can be used to authenticate logins and SSH logins<br />

to the <strong>Sidewinder</strong> <strong>G2</strong>. Web sessions can also be authenticated, but are<br />

limited to using either fixed passwords or passcodes without the<br />

challenge/response option. (Not all tokens support this option.)<br />

The biggest advantages <strong>of</strong> using a tightly coupled configuration such<br />

as SafeWord PremierAccess authentication, are the following:<br />

An improvement in performance over RADIUS<br />

The ability for PremierAccess to forward role information for a<br />

user from the PremierAccess database to the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

(While SafeWord PremierAccess can be connected to <strong>Sidewinder</strong><br />

<strong>G2</strong> via standard RADIUS ports, configurations the user’s role<br />

cannot be made available to the <strong>Sidewinder</strong> <strong>G2</strong>.)<br />

Note: SafeWord RemoteAccess is always connected to the <strong>Sidewinder</strong> <strong>G2</strong> via standard<br />

RADIUS ports and therefore cannot be assigned the SafeWord authentication method.<br />

Aside from the ability to return a user’s role, SafeWord RemoteAccess provides equally<br />

strong user authentication via the RADIUS interface.<br />

LDAP/Active Directory<br />

LDAP (Lightweight Directory Access Protocol)/Active Directory is a<br />

protocol that you can use to provide fixed password authentication<br />

for SOCKS5, Telnet, FTP, and Web sessions through the <strong>Sidewinder</strong><br />

<strong>G2</strong>. It can also be used to authenticate logins and SSH logins to the<br />

<strong>Sidewinder</strong> <strong>G2</strong>. You can set up an LDAP directory server containing<br />

users and passwords. Use any valid combination <strong>of</strong> LDAP attributes<br />

and values as an optional filter string to distinguish authorized<br />

<strong>Sidewinder</strong> <strong>G2</strong> users.<br />

Setting Up Authentication 9-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!