Understanding User Types; Defining Users - Symantec 360R - Security Gateway SGS Administration Manual

Gateway security 300 series
Hide thumbs Also See for 360R - Security Gateway SGS:
Table of Contents

Advertisement

86 Establishing secure VPN connections
Identifying users

Understanding user types

Defining users

Users authenticate directly with the security gateway when connecting through
a VPN tunnel. Users are defined on the security gateway Client Users tab. Users
with extended authentication are not defined on the security gateway; they are
defined on a RADIUS authentication server. You must configure the appliance
to support remote administration of users with extended authentication.
Dynamic users
Dynamic users are not defined on the appliance; rather, they use extended
authentication with RADIUS to authenticate their tunnels. You define dynamic
users on the RADIUS server.
When a dynamic user attempts to authenticate, the appliance looks for that user
name in the defined users list.When it does not find the user there, the appliance
then uses the shared secret that he has entered in the client software. This
shared secret should match the secret on the Advanced screen for the security
gateway to which he is connecting. The appliance then starts extended
authentication and prompts him for whatever information the RADIUS server
requires (such as a user name or password).The RADIUS server authenticates
the user and returns the RADIUS group of the user to the security gateway. The
security gateway checks that the group matches one of the client tunnels and
that the group is allowed to connect to the WAN, LAN, or WLAN. If so, the user's
tunnel is established.
Users
Users authenticate using a client ID (user name) and pre-shared key that you
assign to them. They enter the user name and password in their client software,
that information is sent when they attempt to create a VPN tunnel to the
security gateway.
Users are defined on the appliance, and may also use extended authentication.
Ensure that you obtain all the pertinent authentication information from your
RADIUS administrator to pass on to your users with extended authentication.
To define users
Users must be defined on the appliance, and may also use extended
authentication. Dynamic users must use extended authentication and are not
defined on the appliance.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

320360

Table of Contents