13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring RADIUS server authentication4 To identify the host either:- Enter both the host name and the IP address of the Windows NT network.- Enter the host name. Click Find IP.5 Enable or clear the checkbox labeled Use Local Groups.Enable use the local groups on the authentication host and clear use the global groups on theauthentication host. Consult your Windows NT documentation for details.6 Click Test to ensure the integrity of the host name and IP address.<strong>WatchGuard</strong> searches the network for a matching server. If it finds one, it adds it to the listboxon this tab. If the cursor returns and the listbox remains blank, your host name or IP address isincorrect or the designated server is either not a Windows NT 4.0 server or for some reason iscurrently unavailable. This functionality is not supported on Windows 95 or Windows 98machines.7 Click OK.Configuring RADIUS server authenticationThe Remote Authentication Dial-In <strong>User</strong> Service (RADIUS) provides remote userswith secure access to corporate networks. RADIUS is a client-server system thatstores authentication information for users, remote access servers, and VPN gatewaysin a central user database that is available to all servers. Authentication for the entirenetwork happens from one location.To add or remove services accessible by RADIUS authenticated users, add theRADIUS user or group in the individual service properties dialog box, and the IPaddress of the <strong>Firebox</strong> on the RADIUS authentication server.Although <strong>WatchGuard</strong> supports both CHAP and PAP authentication, CHAP isconsidered more secure.From Policy Manager1 Select Setup => Authentication.The Member Access and Authentication Setup dialog box appears.2 Under Authentication Enabled Via, click the RADIUS Server option.3 Click the RADIUS Server tab.4 Enter the IP address of the RADIUS server.5 Enter or verify the port number used for RADIUS authentication.The default is 1645. (RFC 2138 states the port number as 1812, but many RADIUS servers stilluse post number 1645.)6 Enter the value of the secret shared between the <strong>Firebox</strong> and the RADIUS server.The shared secret is case sensitive and must be identical on the <strong>Firebox</strong> and the RADIUS server.7 Click OK.VPN Manager <strong>Guide</strong> 89

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!