13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring CRYPTOCard server authenticationOn the RADIUS ServerGather the IP address of the <strong>Firebox</strong> and the user or group aliases you wantto authenticate using RADIUS. The aliases appear in the “From” and “To”listboxes for the individual services’ Properties dialog boxes.1 Add the IP address of the <strong>Firebox</strong> where appropriate according to the RADIUSserver vendor.Some RADIUS vendors may not require this. To determine if this is required for yourimplementation, check the RADIUS server vendor documentation.2 Take the user or group aliases gathered from the service properties’ listboxes andadd them to the defined Filter-IDs in the RADIUS configuration file.For example, to add the groups Sales, Marketing, and Engineering enter:Filter-Id=”Sales”Filter-Id=”Marketing”Filter-Id=”Engineering”The filter rules for RADIUS user filter-IDs are case sensitive.For more information, consult the RADIUS server documentation.Configuring CRYPTOCard server authenticationTo add or remove services accessible by CRYPTOCard authenticated users, add theCRYPTOCard user or group in the individual service’s Properties dialog box, and theIP address of the <strong>Firebox</strong> on the CRYPTOCard authentication server.From Policy Manager:1 Select Setup => Authentication.The Member Access and Authentication Setup dialog box appears.2 Under Authentication Enabled Via, click the CRYPTOCard Server option.3 Click the CRYPTOCard Server tab.You might need to use the arrow buttons in the upper-right corner of the dialog box to bring thistab into view.4 Enter the IP address of the CRYPTOCard server.5 Enter or verify the port number used for CRYPTOCard authentication.The standard is 62<strong>4.6</strong> Enter the administrator password.This is the administrator password in the passwd file on the CRYPTOCard server.7 Enter or accept the time-out in seconds.The time-out period is the maximum amount of time, in seconds, a user can wait for theCRYPTOCard server to respond to a request for authentication. Sixty seconds is CRYPTOCard’srecommended time-out length.90

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!