GP- AD auth and SMS through ext radius

Reply
Highlighted
L2 Linker

GP- AD auth and SMS through ext radius

Hi all ,

 

Has anyone accomplished to authenticate external users 1st with AD through LDAP profile and then SMS through radius to another server ? 

 

I guess 1st authentication will done in the portal and SMS auth profile can be added on the gateway  ?

L6 Presenter

Re: GP- AD auth and SMS through ext radius

That would work but the only issue would be if the portal was unavailable...   the GP client would used last cached gateway info and user would only require SMS auth to gateway.

 

 

L2 Linker

Re: GP- AD auth and SMS through ext radius

thank you , so if I want to have the 2nd factor authentication like mentioned how is going to be configured ?  2 auth profiles in one auth sequence attached to both portal and gateway ?

L6 Presenter

Re: GP- AD auth and SMS through ext radius

No, this cannot be done, the auth sequence will finish when the first in the list succeeds.

 

the closest option without using a purpose built MFA is LDAP or Radius combined with certificate..

L2 Linker

Re: GP- AD auth and SMS through ext radius

Can I have LDAP profile to authenticate users against AD for the portal and then use authentication profile with RADIUS for SMS token delivery for the gateway ?

L6 Presenter

Re: GP- AD auth and SMS through ext radius

Yes you can do that.

 

but just be aware...   

 

if the portal ever becomes unavailable the local client will use the last known portal config and attempt to connect to the gateway directly, so only passcode will be required...     this may also be confusing for users as they will not know if to use password or passcode...    

 

why do you feel you need both ?

 

does your sms passcode also require a username and PIN?

L2 Linker

Re: GP- AD auth and SMS through ext radius

I have multiple gateways and that means that Firewalls that have the portals they don't have the gateways and the firewalls with the gateways they don't have any portals .

 

I tried to attach LDAP-AD profile that works in the portal and the profile for the SMS provider to the gateways  which I have configured the firewalls to send vs source-ip only. But doesn't work because it seems that app sends the ad password as passcode since I get SMS that my account is locked but if I do the opposite and I use the SMS auth in the Portal and the LDAP-AP profile in the gateway then I get SMS , I put that since I am getting prompted and then auth fail with no reason but I suspect that this SMS passcode is being used in the gateway .

 

 

L6 Presenter

Re: GP- AD auth and SMS through ext radius

What do you have in network/portal/config/authentication/save user credentials.

 

 

L2 Linker

Re: GP- AD auth and SMS through ext radius

I had save user name only and I tried also with no.

L4 Transporter

Re: GP- AD auth and SMS through ext radius

So in this config Portal and Gateway auth profile should match?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!