Authentication Processing - D-Link NetDefend DFL-210 User Manual

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

8.2.6. Authentication Processing

A further option, Disallow, can be used so that a negative rule can be created which says "never
authenticate given these conditions". This option might be used, for instance, to never
authenticate connections coming in on a particular interface. These Disallow rules are usually
best located at the end of the authentication rule set.
Agent
The type of traffic being authenticated. This can one of:
HTTP or HTTPS - Web connections to be authenticated via a pre-defined or custom web
page (see the detailed HTTP explanation below).
PPP - L2TP or PPTP authentication.
XAUTH - IKE authentication which is part of IPsec tunnel establishment.
The XAuth Agent
XAuth is an extension to the normal IKE exchange and provides an addition to normal IPsec security
which means that clients accessing a VPN must provide a login username and password.
It should be noted that an interface value is not entered with an XAuth authentication rule since one
single rule with XAuth as the agent will be used for all IPsec tunnels. The only limitation with this
approach is that a single authentication database must be used for all IPsec tunnels.
Connection Timeouts
An Authentication Rule can specify the following timeouts related to a user session:
Idle Timeout
How long a connection is idle before being automatically terminated (1800 seconds by default).
Session Timeout
The maximum time that a connection can exist (no value is specified by default).
If an authentication server is being used then the option to Use timeouts received from the
authentication server can be enabled to have these values set from the server.
Multiple Logins
An Authentication Rule can specify how multiple logins are handled where more than one user from
different source IP addresses try to login with the same username. The possible options are:
Allow multiple logins so that more than one client can use the same username/password
combination.
Allow only one login per username.
Allow one login per username and logout an existing user with the same name if they have been
idle for a specific length of time when the new login occurs.
8.2.6. Authentication Processing
The list below describes the processing flow through NetDefendOS for username/password
310
Chapter 8. User Authentication

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents