Advertisement

04.20.2008 at 07:09PM PDT, ID: 23338444
[x]
Attachment Details

How do I configure 2 Factor authentication on ASA Firewall (for SSLVPN) using RSA SecureID and Active Directory

Asked by mr_hil22 in Virtual Private Networking (VPN), IPSec Security Protocol, Enterprise Firewalls

Tags: , , ,

I am trying to setup authentication/authorization for SSLVPN users on ASA firewall.

I know how to setup authentication/authorization server groups and tie that into group-policies or 'tunnel-groups'.

This is what I am looking to do in terms of user experience:

When users try to log in to remote access SSLVPN gateway (ASA firewall) they should 'first' use Active directory credentials (user/pass) and then if that is successful they should get prompted for the SecureID pin (users will have hardware tokens).

All the docs I have gone thru on cisco shows how to setup authentication first using RSA SecureID (SDI or RADIUS) and then configure 'Authorization' using LDAP. Using this method I would get the remote users to first authenticate through RSA SecureID Pin and then they would provide for the LDAP credentials.

Is there a way to authenticate using LDAP first and then provide the second factor using RSA???

Thanks in advance for your answers.
Start Free Trial
[+][-]04.20.2008 at 10:10PM PDT, ID: 21398958

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.21.2008 at 05:36AM PDT, ID: 21400948

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.21.2008 at 08:12AM PDT, ID: 21402698

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Virtual Private Networking (VPN), IPSec Security Protocol, Enterprise Firewalls
Tags: cisco, ASA firewall, 7.x, SSLVPN
Sign Up Now!
Solution Provided By: arnold
Participating Experts: 1
Solution Grade: B
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628