12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring RADIUS Server AuthenticationConfiguring RADIUS Server AuthenticationRemote Authentication Dial-In <strong>User</strong> Service (RADIUS) authenticates the local users and remote users ona company network. RADIUS is a client/server system that keeps the authentication information forusers, remote access servers, VPN gateways, and other resources in one central database.The authentication messages to and from the RADIUS server always use an authentication key. Thisauthentication key, or shared secret, must be the same on the RADIUS client and server. Without thiskey, hackers cannot get to the authentication messages. Note that RADIUS sends a key, and not a password,during authentication. For web and MUVPN authentication, RADIUS supports only PAP (notCHAP) authentication. For authentication with PPTP, RADIUS supports only MSCHAPv2.To use RADIUS server authentication with the Firebox®, you must:• Add the IP address of the Firebox to the RADIUS server, as described in the RADIUSdocumentation.• Enable and specify the RADIUS server in your Firebox configuration.• Add RADIUS user names or group names into the policies in Policy Manager.To enable RADIUS Server Authentication:1 From Policy Manager, select Setup > Authentication Servers. Click the RADIUS Server tab.The RADIUS configuration appears.2 In the IP Address box, type the IP address of the RADIUS server.3 In the Port box, make sure that the port number RADIUS uses for authentication appears.The default port number is 1812. Older RADIUS servers might use port 1645.4 In the Secret box, type the shared secret between the Firebox and the RADIUS server.The shared secret is a password that is case-sensitive, and it must be the same on the Firebox and the RADIUSserver.5 To set the time-out value, use the Timeout value control to set the value you want.This sets how long the Firebox waits for a response from the authentication server before it tries to connect again.<strong>User</strong> <strong>Guide</strong> 127

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!