PUBLIC Sony DADC Austria AG Information Systems Juniper SSL-VPN Login with On- Demand Tokencode Authentication for Customer and Partner Extranet V1.0 13.07.2012 / Rene Lösch Sony DADC Austria AG Information Systems Sonystraße 20 5081 Anif, Austria Phone +43 (0) 6246-880-0
PUBLIC - 2 / 7 - Sony DADC IT Table of Contents 1 Document Data... 3 1.1 Security Classification... 3 1.2 Document Status... 3 1.3 Version History... 3 1.4 Document Scope... 3 1.4.1 Technical... 3 1.4.2 Organizational... 3 1.5 Abbreviations... 3 1.6 Symbols... 3 2 Login Procedure... 4 2.1 Pre Sign-In Notification... 4 2.2 Host Verification... 4 2.3 Login-Page... 5 2.4 Change PIN at first use... 5 2.5 SMS-Tokencode... 6 2.6 Juniper Secure Access Start Page... 7
PUBLIC - 3 / 7 - Sony DADC IT 1 Document Data This section contains the relevant information for document controlling and classification. 1.1 Security Classification PUBLIC [SECRET / CONFIDENTIAL / INTERNAL USE ONLY / PUBLIC] 1.2 Document Status DRAFT [DRAFT / PROPOSED / APPROVED / NOT IN USE] 1.3 Version History Date Version Author Changes 13.07.2012 0.1 Rene Lösch Initial Draft 06.08.2012 1.0 Rene Lösch Published 1.4 Document Scope 1.4.1 Technical The document descripts the Juniper SSL VPN login-procedure via RSA On-Demand Authentication, also called SMS Tokencode at Sony DADC Austria AG. 1.4.2 Organizational The document is an end-user guide for Sony DADC Austria AG s customers and partners. 1.5 Abbreviations Abbreviation SSL-VPN SMS PIN OTP AD Description virtual private network thru Secure Socket Layer encryption short message service personal identification number One-Time-Password Active Directory (Microsoft Directory Service for Windows) 1.6 Symbols Bullet point Reference to other chapter Important information about the current chapter
PUBLIC - 4 / 7 - Sony DADC IT 2 Login Procedure This section describes the login procedure for the Customer and Partner Extranet on Sony DADC SSL-VPN gateway (https://sslvpn.sonydadc.com/extranet) via SMS Tokencode authentication. 2.1 Pre Sign-In Notification After accessing the Sony DADC SSL-VPN gateway (hereinafter SSLVPN) a Pre Sign-In Notification appears (Figure 1). Read this notification and continue by clicking on Proceed. Figure 1: Pre Sign-In Notification 2.2 Host Verification The Host Checker verifies if the computer meets the required security conditions. This is necessary each time before SSLVPN can be used (Figure 2). Figure 2: Host Checker
PUBLIC - 5 / 7 - Sony DADC IT 2.3 Login-Page After a successfully verification the login page appears (Figure 3). Enter username, PIN (OTP PIN for On-Demand Tokencode authentication), password and click on Sign In to continue. Figure 3: Login Page for Extranet 2.4 Change PIN at first use When the authentication method via On-Demand Tokencode is used for the first time, the preassigned PIN has to be changed (Figure 4). Figure 4: New PIN required After changing the PIN a re-login with the new PIN is required (Figure 5). The other credentials are the same as before.
PUBLIC - 6 / 7 - Sony DADC IT Figure 5: Login Page after PIN replace 2.5 SMS-Tokencode After clicking on Sign In the page for entering the received Tokencode appears this time (Figure 6). This code is sent to the user s mobile phone number or e-mail address and will be transmit within a few seconds. The validity of this code ends after five minutes or use. Figure 6: SMS-Tokencode entry
PUBLIC - 7 / 7 - Sony DADC IT 2.6 Juniper Secure Access Start Page After a successful authentication SSLVPN s start page is shown (Figure 7), there all accessible applications of logged-in user are listed. Figure 7: SSLVPN Start Page