Juniper NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING INFRANET CONTROLLER GUIDE REV 01 Manual page 63

Configuring infranet controllers guide
Hide thumbs Also See for NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING INFRANET CONTROLLER GUIDE REV 01:
Table of Contents

Advertisement

Copyright © 2010, Juniper Networks, Inc.
Table 8: OAC Configuration Details (continued)
Option
Function
Select protocol
Specifies whether the
for outer
outer authentication
authentication
protocol for traffic
between Odyssey Access
Client and the Infranet
Controller are Tunneled
TLS (TTLS) or Protected
EAP (PEAP).
Anonymous
Enables users to appear
name
to log in anonymously
while passing the user's
login name (called the
inner identity) through an
encrypted tunnel. As a
result, the user's
credentials are secure
from eavesdropping and
the user's inner identity is
protected.
Chapter 6: Configuring User Roles and Administrator Roles
Your Action
Select the protocol for outer authentication:
If you select Use EAP-TTLS as outer
authentication protocol and you want to use
a client certificate as part of the EAP-TTLS
authentication, click the eap-ttls button and
select Use the user's certificate and perform
inner authentication. This option uses
EAP-TTLS certificate-based authentication
and tunnels password credentials with inner
authentication. Note that the most typical use
of EAP-TTLS authentication is without a client
certificate.
If you select Use EAP-PEAP as outer
authentication protocol and you want to use
a client certificate as part of the EAP-PEAP
authentication, click the eap-peap button and
select Inner authentication is required.
NOTE:
Only enable the personal client certificate
option for either EAP-TTLS or EAPPEAP to
use a client certificate if you also configure a
realm or role to require a client certificate on
the endpoint. If you enable the personal client
certificate option and do not configure the
realm or role certificate restriction, you will
cause unnecessary restrictions on the use of
this Odyssey Access Client profile.
If you enable the personal client certificate
option, the Infranet Controller automatically
selects Permit login using my Certificate and
Use automatic certificate selection in the
Odyssey Access Client profile.
As a general rule enter anonymous in the
Anonymous name box, which is the default
value. In some cases, you may need to add
additional text. For example, if the outer identity
is used to route the user's authentication to the
proper server, you may be required to use a
format such as anonymous@acme.com. If you
leave the Anonymous name box blank, Odyssey
Access Client passes the user's login name (inner
identity) as the outer identity.
45

Advertisement

Table of Contents
loading

Table of Contents