Hi all ,
Has anyone accomplished to authenticate external users 1st with AD through LDAP profile and then SMS through radius to another server ?
I guess 1st authentication will done in the portal and SMS auth profile can be added on the gateway ?
Solved! Go to Solution.
That would work but the only issue would be if the portal was unavailable... the GP client would used last cached gateway info and user would only require SMS auth to gateway.
thank you , so if I want to have the 2nd factor authentication like mentioned how is going to be configured ? 2 auth profiles in one auth sequence attached to both portal and gateway ?
Can I have LDAP profile to authenticate users against AD for the portal and then use authentication profile with RADIUS for SMS token delivery for the gateway ?
Yes you can do that.
but just be aware...
if the portal ever becomes unavailable the local client will use the last known portal config and attempt to connect to the gateway directly, so only passcode will be required... this may also be confusing for users as they will not know if to use password or passcode...
why do you feel you need both ?
does your sms passcode also require a username and PIN?
I have multiple gateways and that means that Firewalls that have the portals they don't have the gateways and the firewalls with the gateways they don't have any portals .
I tried to attach LDAP-AD profile that works in the portal and the profile for the SMS provider to the gateways which I have configured the firewalls to send vs source-ip only. But doesn't work because it seems that app sends the ad password as passcode since I get SMS that my account is locked but if I do the opposite and I use the SMS auth in the Portal and the LDAP-AP profile in the gateway then I get SMS , I put that since I am getting prompted and then auth fail with no reason but I suspect that this SMS passcode is being used in the gateway .
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!