Radius and nt domain authentication, Configuring for radius domain authentication, Radius and nt domain authentication -3 – NETGEAR ProSafe SSL312 User Manual

Page 37: Configuring for radius domain authentication -3

Advertising
background image

NETGEAR ProSafe SSL VPN Concentrator 25 SSL312 Reference Manual

Authenticating Users

3-3

v1.1, November 2006

4. In the Portal Layout Name pull-down menu, select the name of the layout. The default layout

is SSL-VPN. You can define additional layouts in the Portal Layouts screen.

5. To force users to supply a valid digital certificate before granting access, check the Require

client digital certificates radio box. The CNAME of the client certificate must match the user
name that the user supplies to log in and the certificate must be generated by a certificate
authority (CA) that is trusted by SSL VPN Concentrator.

6. Click Apply to update the configuration. Once the domain has been added, the domain is

displayed in the table on the Domains screen

RADIUS and NT Domain Authentication

For authentication to RADIUS or Microsoft NT domains (using Kerberos), you can individually
define authentication, authorization, and accounting (AAA) users and groups. This is not required,
but it allows you to create separate policies or bookmarks for individual AAA users.

When a user logs in, the SSL VPN Concentrator will validate with the appropriate RADIUS or NT
server that the user is authorized to log in. If the user is authorized, the SSL VPN Concentrator will
check to see if a user exists in the SSL VPN Concentrator Users and Groups database. If the user is
defined, then the policies and bookmarks defined for the user will apply.

For example, if you create a RADIUS domain in the SSL VPN Concentrator called “Miami
RADIUS server”, you can add users to groups that are members of the “Miami RADIUS server”
domain. These user names must match the names configured in the RADIUS server. Then, when
users log in to the portal, policies, bookmarks and other user settings will apply to the users. If the
AAA user does not exist in the SSL VPN Concentrator, then only the global settings, policies and
bookmarks will apply to the user.

Configuring for RADIUS Domain Authentication

To create a domain with Radius authentication:

1. Click Add Domain. An Add Domain window displays.

Advertising