External Authentication with Netscreen 25 Remote VPN Authenticating Users Using SecurAccess Server by SecurEnvoy



Similar documents
External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Citrix Access Gateway Advanced Edition

Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with CiscoSecure ACS. Authenticating Users Using. SecurAccess Server. by SecurEnvoy

External Authentication with Checkpoint R75.40 Authenticating Users Using SecurAccess Server by SecurEnvoy

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

External Authentication with Windows 2008 Server with Routing and Remote Access Service Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco Router with VPN and Cisco EZVpn client Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Windows 2012 R2 Server with Remote Desktop Web Gateway Authenticating Users Using SecurAccess Server by SecurEnvoy

Full disk encryption with Sophos Safeguard Enterprise With Two-Factor authentication of Users Using SecurAccess by SecurEnvoy

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Microsoft Outlook Web Access 2013 Authenticating Users Using SecurAccess Server by SecurEnvoy

Configuring Global Protect SSL VPN with a user-defined port

DIGIPASS Authentication for Juniper ScreenOS

How To Configure Apple ipad for Cyberoam L2TP

How To Setup Cyberoam VPN Client to connect a Cyberoam for remote access using preshared key

SSH to Ubuntu Server Authenticating Users Using SecurAccess Server by SecurEnvoy

How To - Setup Cyberoam VPN Client to connect to a Cyberoam for the remote access using preshared key

Application Note. Using a Windows NT Domain / Active Directory for User Authentication NetScreen Devices 8/15/02 Jay Ratford Version 1.

Application Note: Integrate Juniper IPSec VPN with Gemalto SA Server. October

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

SecurEnvoy IIS Web Agent. Version 7.2

SecurEnvoy Reporting Wizard

How to integrate RSA ACE Server SecurID Authentication with Juniper Networks Secure Access SSL VPN (SA) with Single Node or Cluster (A/A or A/P)

SecurEnvoy Windows Login Agent

ZyWALL OTPv2 Support Notes

Dial-Up VPN auf eine Juniper

DIGIPASS Authentication for SonicWALL SSL-VPN

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access. Integration Handbook

ZyWALL OTP Co works with Active Directory Not Only Enhances Password Security but Also Simplifies Account Management

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

Juniper NetScreen 5GT

Scenario: IPsec Remote-Access VPN Configuration

Integration Guide. Swivel Secure Authentication

Product Guide Addendum. SafeWord Check Point User Management Console Version 2.1

Accessing the Media General SSL VPN

Configuring the Watchguard Edge for RADIUS authentication

How To Connect A Gemalto To A Germanto Server To A Joniper Ssl Vpn On A Pb.Net 2.Net (Net 2) On A Gmaalto.Com Web Server

Scenario: Remote-Access VPN Configuration

Chapter 6 Virtual Private Networking

HOTPin Integration Guide: DirectAccess

Cox Managed CPE Services. RADIUS Authentication for AnyConnect VPN Version 1.3 [Draft]

DIGIPASS Authentication for GajShield GS Series

A brief on Two-Factor Authentication

Juniper Networks SSL VPN Implementation Guide

Palo Alto Networks GlobalProtect VPN configuration for SMS PASSCODE SMS PASSCODE 2015

Check Point FW-1/VPN-1 NG/FP3

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

RSA SecurID Ready Implementation Guide

Create a VPN on your ipad, iphone or ipod Touch and SonicWALL NSA UTM firewall - Part 1: SonicWALL NSA Appliance

Global VPN Client Getting Started Guide

How-to: HTTP-Proxy and Radius Authentication and Windows IAS Server settings. Securepoint Security System Version 2007nx

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

Borderware Firewall Server Version 7.1. VPN Authentication Configuration Guide. Copyright 2005 CRYPTOCard Corporation All Rights Reserved

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Network/VPN Overlap How-To with SonicOS 2.0 Enhanced Updated 9/26/03 SonicWALL,Inc.

Step by Step Guide to implement SMS authentication to F5 Big-IP APM (Access Policy Manager)

Stonesoft Corp. Stonegate Firewall and VPN

Defender Token Deployment System Quick Start Guide

Configuring the Palo Alto Firewall for use with Juniper Steel-Belted RADIUS.

Strong Authentication for Juniper Networks

DIGIPASS Authentication for Cisco ASA 5500 Series

How to Configure NetScaler Gateway 10.5 to use with StoreFront 2.6 and XenDesktop 7.6.

Multi-factor Authentication using Radius

Configuring IPsec VPN with a FortiGate and a Cisco ASA

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

SecurEnvoy Security Server Installation Guide

Configuring User Identification via Active Directory

TechNote. Contents. Introduction. System Requirements. SRA Two-factor Authentication with Quest Defender. Secure Remote Access.

IIS, FTP Server and Windows

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

Configuring a VPN for Dynamic IP Address Connections

ESET SECURE AUTHENTICATION. Cisco ASA Internet Protocol Security (IPSec) VPN Integration Guide

WHITE PAPER Citrix Secure Gateway Startup Guide

How To Configure L2TP VPN Connection for MAC OS X client

Establishing two-factor authentication with Cyberoam UTM appliances and HOTPin authentication server from Celestix Networks

Defender EAP Agent Installation and Configuration Guide

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Introduction to Mobile Access Gateway Installation

RSA Authentication Manager 7.1 Basic Exercises

How to Configure Active Directory based User Authentication

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

Establishing two-factor authentication with Barracuda NG Firewall and HOTPin authentication server from Celestix Networks

Two-Factor Authentication

Configure VPN between ProSafe VPN Client Software and FVG318

How To Configure A Bomgar.Com To Authenticate To A Rdius Server For Multi Factor Authentication

BlackShield ID Best Practice

NAS 323 Using Your NAS as a VPN Server

Advanced Administration

Transcription:

External Authentication with Netscreen 25 Remote VPN Authenticating Users Using SecurAccess Server by SecurEnvoy Contact information SecurEnvoy www.securenvoy.com 0845 2600010 1210 Parkview Arlington Business Park Theale Reading RG7 4TY Phil Underwood Punderwood@securenvoy.com

This document describes how to integrate Juniper Remote Access VPN with SecurEnvoy two-factor Authentication solution called SecurAccess Juniper Remote Access VPN provides - Secure Remote Access to corporate network resources for all Client/Server applications. SecurAccess provides two-factor, strong authentication for remote Access solutions (such as Juniper Remote Access VPN), without the complication of deploying hardware tokens or smartcards. Two-Factor authentication is provided by the use of (your PIN and your Phone to receive the one time passcode) SecurAccess is designed as an easy to deploy and use technology. It integrates directly into Microsoft s Active Directory and negates the need for additional User Security databases. SecurAccess consists of two core elements: a Radius Server and Authentication server. The Authentication server is directly integrated with LDAP or Active Directory in real time. Juniper Remote Access can be configured in such a way that it can proxy the Authentication request of the users to an external directory (such as Radius). This is how the Juniper Remote Access VPN was configured. All authentication requests were forwarded to SecurEnvoy Authentication server. Both Juniper and SecurEnvoy utilize a web GUI for configuration. All notes within this integration guide refer to this type of approach. The equipment used for the integration process is listed below Juniper Netscreen Firewall VPN Hardware Version: 4010(0) Firmware Version: 5.1.0r3.0 (Firewall+VPN) Microsoft Windows 2000 server SP4 IIS installed with SSL certificate (required for management and remote administration) Active Directory installed SecurEnvoy SecurAccess software release v2.7 0100

Log into the Juniper Networks Netscreen-25 Administrator Console. The administrator console can be reached via a web browser In the Administrator Console, choose Configuration/Auth/Auth Server, click on new server. Populate the fields to reflect the network setup. The Name is a label used in the Juniper Networks Netscreen Firewall to refer to the SecurEnvoy Authentication server. It is NOT the name associated with a DNS entry. The IP/Domain Name should be either the IP address or the FQDN of the SecurEnvoy Server. Select Timeout and enter a value of at least 10 seconds, set the account type to XAuth. Select Radius and enter port and Pre-Shared key values, these values must be reflected within the configuration of the SecurEnvoy Radius settings (shown later).

Create a User Group and create Users who will have VPN access with SecurEnvoy authentication. Go to Objects/User Groups/Local Create a group Called SecurEnvoy Group and select members to be added to this group. Click Ok when completed. Note: Users must be create before they can be added to the User Group Go to Objects/Users/Local Create new user, enable and select them as an IKE user, populate which mechanism they will use for IKE identity. Click Ok when completed.

Establish the VPN settings Go to VPN s/auto Key Advanced/Gateway Create a new VPN gateway enter SecurEnvoy Gateway as the name for this new entry select custom security level, select dial-up user group and select the group you defined earlier in the drop-down box SecurEnvoy Group. Populate the pre-shred key for Phase 1 VPN configuration. This must match on both the VPN client and Netscreen 25. Then click on the Advanced button. Continue building the VPN Gateway under Advanced by clicking on user Defined and selecting a series of Phase 1 Proposals. Check the Enable Xauth box. Select the External Authentication radio button and select the name given to your SecurEnvoy Server. Click the Return button and then the OK button to conclude building the Gateway

Continue with the VPN Setup Go to VPN/AutoKey IKE. Click on the New button. Define a new VPN here by giving it a name, select custom for the security level, and choose Predefined for the Remote Gateway. Then select the gateway you just defined from the drop-down box SecurEnvoy Gateway. Click on the Advanced button. Continue defining the VPN under Advanced by defining a Phase 2 proposal. Select Tunnel Zone within the Bind to field.

Create a Policy from Untrust to Trust. The source will be from the address book entry Dial-Up VPN and the Destination will be the trusted network. Under Action, choose tunnel. For the tunnel, chose the tunnel you defined in the prior step. Click Ok when complete. To set up Radius on SecurEnvoy SecurAccess, launch local Security Server Administration Select Radius Enter NAS IP address Enter Radius Shared Secret Click Send NOTE: Netscreen VPN requires a RADIUS accounting server or it will fail authentication! A Microsoft IAS service must be installed to act at the RADIUS accounting only.

Install Microsoft IAS, this is a windows service on Microsoft Windows 2000 and 2003 server. This has to be installed on the same server as the SecurEnvoy SecurAccess server. Set up the IAS server so that the authentication port is an unused port as this service is not required, keep the accountancy port set to default. Create a new Radius client entry for the Netscreen VPN Firewall, the Radius shared secret will be the same as the Radius shared secret for the SecurEnvoy Radius server.

Therefore the Radius authentication request will be answered by the SecurEnvoy server and the accountancy information will be logged by the Microsoft IAS server. Test Authentication Carry out a test authentication, launch VPN client Enter Username, Pin and Passcode into the relevant fields.