D-Link NetDefend DFL-210 User Manual page 327

Network security firewall ver 2.26.01
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

8.2.5. Authentication Rules
Interface
The source interface on which the connections to be authenticated will arrive.
Source IP
The source network from which new connections will arrive.
Authentication Source
- This specifies that authentication is to be done against one of the following:
The Local database defined within NetDefendOS.
A RADIUS server (discussed below).
An external LDAP server database (discussed below).
A further option, Disallow, can be used so that a negative rule can be created which says "never
authenticate given these conditions". This option might be used, for instance, to never
authenticate connections coming in on a particular interface. These Disallow rules are usually
best located at the end of the authentication rule set.
Agent
The type of traffic being authenticated. This can one of:
HTTP or HTTPS - Web connections to be authenticated via a predefined or custom web
page (see the detailed HTTP explanation below).
PPP - L2TP or PPTP authentication.
XAUTH - IKE authentication which is part of IPsec tunnel establishment.
The XAuth Agent
XAuth is an extension to the normal IKE exchange and provides an addition to normal IPsec security
which means that clients accessing a VPN must provide a login username and password.
It should be noted that an interface value is not entered with an XAuth authentication rule since one
single rule with XAuth as the agent will be used for all IPsec tunnels. The only limitation with this
approach is that a single authentication database must be used for all IPsec tunnels.
Connection Timeouts
An Authentication Rule can specify the following timeouts related to a user session:
Idle Timeout
How long a connection is idle before being automatically terminated (1800 seconds by default).
Session Timeout
The maximum time that a connection can exist (no value is specified by default).
If an authentication server is being used then the option to Use timeouts received from the
authentication server can be enabled to have these values set from the server.
Multiple Logins
327
Chapter 8. User Authentication

Advertisement

Table of Contents
loading

Table of Contents