14.02.2014 Views

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Appendix G Two-Factor Authentication<br />

CC-SG can be configured to point to an RSA RADIUS Server that<br />

supports two-factor authentication via an associated RSA Authentication<br />

Manager. CC-SG acts as a RADIUS client and sends user authentication<br />

requests to RSA RADIUS Server. The authentication request includes<br />

user id, a fixed password, and a dynamic token code.<br />

In This Chapter<br />

Supported Environments for Two-Factor Authentication ......................304<br />

Two-Factor Authentication Setup Requirements...................................304<br />

Two-Factor Authentication Known Issues .............................................304<br />

Supported Environments for Two-Factor Authentication<br />

The following two-factor authentication components are known to work<br />

with CC-SG.<br />

• RSA RADIUS Server 6.1 on Windows Server 2003<br />

• RSA Authentication Manager 6.1 on Windows Server 2003<br />

• RSA <strong>Secure</strong> ID SID700 hardware token<br />

Earlier RSA product versions should also work with CC-SG, but they have<br />

not been verified.<br />

Two-Factor Authentication Setup Requirements<br />

The following tasks must be completed for two-factor authentication setup.<br />

Consult the RSA documentation.<br />

1. Import tokens.<br />

2. Create a CC-SG user and assign a token to the user.<br />

3. Generate a user password.<br />

4. Create an agent host for the RADIUS server.<br />

5. Create an agent host (type: Communication Server) for CC-SG.<br />

6. Create a RADIUS CC-SG client.<br />

Two-Factor Authentication Known Issues<br />

The RSA RADIUS “New PIN” mode that requires a challenge<br />

password/PIN will not work. Instead, all users in this scheme must be<br />

assigned fixed passwords.<br />

304

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!