How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F



Similar documents
External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Checkpoint R75.40 Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with CiscoSecure ACS. Authenticating Users Using. SecurAccess Server. by SecurEnvoy

External Authentication with Citrix Access Gateway Advanced Edition

External Authentication with Windows 2008 Server with Routing and Remote Access Service Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Windows 2012 R2 Server with Remote Desktop Web Gateway Authenticating Users Using SecurAccess Server by SecurEnvoy

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

Full disk encryption with Sophos Safeguard Enterprise With Two-Factor authentication of Users Using SecurAccess by SecurEnvoy

External Authentication with Netscreen 25 Remote VPN Authenticating Users Using SecurAccess Server by SecurEnvoy

Microsoft Outlook Web Access 2013 Authenticating Users Using SecurAccess Server by SecurEnvoy

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

External Authentication with Cisco Router with VPN and Cisco EZVpn client Authenticating Users Using SecurAccess Server by SecurEnvoy

SSH to Ubuntu Server Authenticating Users Using SecurAccess Server by SecurEnvoy

SecurEnvoy Windows Login Agent

SecurEnvoy IIS Web Agent. Version 7.2

ZyWALL OTP Co works with Active Directory Not Only Enhances Password Security but Also Simplifies Account Management

SecurEnvoy Reporting Wizard

Configuring User Identification via Active Directory

Integration Guide. Duo Security Authentication

Configuring Color Access on the WorkCentre 7120 Using Microsoft Active Directory Customer Tip

Authentication Node Configuration. WatchGuard XTM

Defender Token Deployment System Quick Start Guide

Accessing the Media General SSL VPN

Customer Tips. Configuring Color Access on the WorkCentre 7328/7335/7345 using Windows Active Directory. for the user. Overview

Palo Alto Networks GlobalProtect VPN configuration for SMS PASSCODE SMS PASSCODE 2015

BlackShield ID Best Practice

Two-Factor Authentication

HOTPin Integration Guide: DirectAccess

Step by Step Guide to implement SMS authentication to F5 Big-IP APM (Access Policy Manager)

SecurEnvoy Security Server Installation Guide

A brief on Two-Factor Authentication

Access to Webmail services via a Non Trust Computer

Cisco ASA. Implementation Guide. (Version 5.4) Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

DualShield. for. Microsoft TMG. Implementation Guide. (Version 5.2) Copyright 2011 Deepnet Security Limited

Multi-factor Authentication using Radius

ESET SECURE AUTHENTICATION. Cisco ASA SSL VPN Integration Guide

Step by step guide to implement SMS authentication to Cisco ASA Clientless SSL VPN and Cisco VPN

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

SecurEnvoy Security Server Administration Guide

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Configuring the Watchguard Edge for RADIUS authentication

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

How to Configure Active Directory based User Authentication

Configure Single Sign on Between Domino and WPS

Defender EAP Agent Installation and Configuration Guide

Configuring the Cisco ISA500 for Active Directory/LDAP and RADIUS Authentication

ESET SECURE AUTHENTICATION. Check Point Software SSL VPN Integration Guide

NSi Mobile Installation Guide. Version 6.2

TechNote. Contents. Introduction. System Requirements. SRA Two-factor Authentication with Quest Defender. Secure Remote Access.

INTEGRATION GUIDE. DIGIPASS Authentication for Juniper SSL-VPN

Integration Guide. Swivel Secure Authentication

DIGIPASS Authentication for Sonicwall Aventail SSL VPN

Establishing two-factor authentication with Barracuda NG Firewall and HOTPin authentication server from Celestix Networks

NetMotion + YubiRADIUS Quick Start Guide

BlackShield ID Agent for Remote Web Workplace

Configuring Global Protect SSL VPN with a user-defined port

Deploying RSA ClearTrust with the FirePass controller

ZyWALL OTPv2 Support Notes

ESET SECURE AUTHENTICATION. Cisco ASA Internet Protocol Security (IPSec) VPN Integration Guide

BlackShield ID Agent for Terminal Services Web and Remote Desktop Web

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access. Integration Handbook

Hosted Microsoft Exchange Client Setup & Guide Book

Application Note. ShoreTel 9: Active Directory Integration. Integration checklist. AN June 2009

SETTING UP REMOTE ACCESS ON EYEMAX PC BASED DVR.

IIS, FTP Server and Windows

How to Logon with Domain Credentials to a Server in a Workgroup

McAfee One Time Password

Hosted Microsoft Exchange Client Setup & Guide Book

How to set up Outlook Anywhere on your home system

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

How To Set Up Chime For A Coworker On Windows (Windows) With A Windows 7 (Windows 7) On A Windows 8.1 (Windows 8) With An Ipad (Windows).Net (Windows Xp

DIS VPN Service Client Documentation

Establishing two-factor authentication with Cyberoam UTM appliances and HOTPin authentication server from Celestix Networks

Using the Content Distribution Manager GUI

DIGIPASS Authentication for SonicWALL SSL-VPN

How to integrate RSA ACE Server SecurID Authentication with Juniper Networks Secure Access SSL VPN (SA) with Single Node or Cluster (A/A or A/P)

Establishing two-factor authentication with Check Point and HOTPin authentication server from Celestix Networks

setup information for most domains hosted with InfoRailway.

ESET SECURE AUTHENTICATION. SonicWall SSL VPN Integration Guide

F-Secure Messaging Security Gateway. Deployment Guide

Microsoft IAS Configuration for RADIUS Authorization

OneLogin Integration User Guide

For paid computer support call

Note that if at any time during the setup process you are asked to login, click either Cancel or Work Offline depending upon the prompt.

INTEGRATION GUIDE. DIGIPASS Authentication for Cisco ASA 5505

MIGRATION GUIDE. Authentication Server

Cloud Services ADM. Agent Deployment Guide

Windows XP Exchange Client Installation Instructions

SafeWord Domain Login Agent Step-by-Step Guide

netld External Authentication Setup Guide

Transcription:

External Authentication with Watchguard XTM Authenticating Users Using SecurAccess Server by SecurEnvoy Contact information SecurEnvoy www.securenvoy.com 0845 2600010 1210 Parkview Arlington Business Park Theale Reading RG7 4TY Phil Underwood Punderwood@securenvoy.com

Watchguard XTM Integration Guide This document describes how to integrate a Watchguard XTM with SecurEnvoy twofactor Authentication solution called SecurAccess. Watchguard XTM provides Secure Remote Access and Firewalling to the internal corporate network. SecurAccess provides two-factor, strong authentication for remote Access solutions (such as Watchguard), without the complication of deploying hardware tokens or smartcards. Two-Factor authentication is provided by the use of (your PIN and your Phone to receive the one time passcode) SecurAccess is designed as an easy to deploy and use technology. It integrates directly into any LDAP server and negates the need for additional User Security databases. SecurAccess consists of two core elements: a Radius Server and Authentication server. The Authentication server is directly integrated with LDAP in real time. SecurEnvoy Security Server can be configured in such a way that it can use the existing LDAP password. Utilising the LDAP password as the PIN, allows the User to enter their UserID, Domain password and One Time Passcode received upon their mobile phone. This authentication request is passed via the Radius protocol to the SecurEnvoy Radius server where it carries out a Two-Factor authentication. It provides a seemless login into the Windows Server environment by entering three pieces of information. SecurEnvoy utilises a web GUI for configuration, whereas Watchguard XTM uses a thick client (System Manger). All notes within this integration guide refer to this type of approach. The equipment used for the integration process is listed below: Watchguard Watchguard XTM v11.7.4 SecurEnvoy Windows 2012 server IIS installed with SSL certificate (required for management and remote administration) Active Directory installed or connection to Active Directory via LDAP protocol. SecurAccess software release v7.1.503 2013 SecurEnvoy Plc. All rights reserved Confidential Page 2

Index 1.0 Pre Requisites... 3 1.1 Configuration of Watchguard XTM... 4 1.2 Configuration of Watchguard XTM SSL VPN... 4 2.0 Configuration of SecurEnvoy - PIN configuration... 6 2.1 Configuration of SecurEnvoy - RADIUS configuration... 6 3.0 Test logon... 7 1.0 Pre Requisites It is assumed that the Watchguard XTM has been installed and is authenticating VPN users with a username and password. Securenvoy Security Server has been installed with the Radius service and has a suitable account that has read and write privileges to the Active Directory, if firewalls are between the SecurEnvoy Security server, Active Directory servers, and the Routing and Remote Access server(s), additional open ports will be required. NOTE: Add radius profiles for each Watchguard XTM that requires Two-Factor Authentication. 2013 SecurEnvoy Plc. All rights reserved Confidential Page 3

1.1 Configuration of Watchguard XTM To enable configuration launch the Watchguard System Manager. Navigate to VPN Menu, select Mobile VPN and SSL. 1.2 Configuration of Watchguard XTM SSL VPN Within the Mobile VPN with SSL configuration, on the General tab, select Activate and configure the IP address that user will connect to. Click OK when complete. 2013 SecurEnvoy Plc. All rights reserved Confidential Page 4

Select the Authentication tab. Then select RADIUS as the authentication server. If required an LDAP group can be assigned as the authentication group to use RADIUS. In this example a WatchGuard_VPN group was created on Active Directory (LDAP). Click Configure to set RADIUS parameters. Then select RADIUS. Enable RADIUS and set IP address details, port and Shared secret for the SecurEnvoy server. It is recommended that a timeout of at least 5 seconds is used. Click OK to complete. Once complete, additional rules are automatically added to the Firewall configuration to allow SSL VPN users access. Save configuration, when complete. 2013 SecurEnvoy Plc. All rights reserved Confidential Page 5

2.0 Configuration of SecurEnvoy - PIN configuration To help facilitate an easy to use environment, SecurEnvoy can utilise the existing LDAP password as the PIN. This allows the users to only remember their Domain password. SecurEnvoy supplies the second factor of authentication, which is the dynamic one time passcode (OTP) which is sent to the user s mobile phone via SMS. Launch the SecurEnvoy admin interface, by executing the Local Security Server Administration link on the SecurEnvoy Security Server. Click Config Select Windows Microsoft Password is the PIN under PIN Management This will now use the users existing password as the PIN. Click Update to confirm the changes 2.1 Configuration of SecurEnvoy - RADIUS configuration Click the Radius Button Enter IP address and Shared secret for each Watchguard XTM that wishes to use SecurEnvoy Two-Factor authentication. Make sure that Access-Challenge All is selected. As a Watchguard_VPN group was configured upon the Watchguard XTM device, select LDAP group members are passed back. Leave the (Return distinguished names) unticked. Click Update to confirm settings. Click Logout when finished. This will log out of the Administrative session. 2013 SecurEnvoy Plc. All rights reserved Confidential Page 6

3.0 Test logon Navigate to the URL that is supplied by your Watchguard XTM administrator. Enter your Domain UserID and Domain password Click Login You will then be prompted to enter your 6 digit passcode. Enter your 6 digit passcode, from SMS, email or soft token etc. Click Apply to complete the logon process. Once the authentication request is complete, the user is provided with access. 2013 SecurEnvoy Plc. All rights reserved Confidential Page 7