Forum Discussion
Jon_Ole_Nome_46
Nimbostratus
Jan 14, 20112-factor code via SMS iRule
We have a need for 2-factor auth on some of our external services, and are looking at alternatives to the current SecurID setup. Would it be possible to have an iiRule to generate a random code, send out via SMS provider, and wait for the user to receive the code on his mobile phone, enter as part of the APM login and compare the codes for accept/deny. Thanks for any feedback!
Jon Ole
- hoolio
Cirrostratus
Hi Jon, - Jon_Ole_Nome_46
Nimbostratus
We are currently using Clickatell for SMS distribution, and the SMS is sent by sending a http request to the provider that includes our login/password and phone number and message (code), I believe many mobile operators support this type of functionallity. - hoolio
Cirrostratus
You could potentially do that now using HTTP::retry: - Jon_Ole_Nome_46
Nimbostratus
Thank you, Aaron! The HTTP::retry looks very promising. The wiki for HTTP::retry (http://devcentral.f5.com/wiki/default.aspx/iRules/HTTP__retry.html) had exactly the example I have been looking for. If that works as advertised we only need a random number generator within the irule to complete the job.Btw. we have opened an RFE with F5, and were told that they were working on getting this functionality into future versions of the APM. For a short-term solution we were asked to use the forums at DevCentral, and they were right :-)
Here is a short description of how Checkpoint has integrated the same thing into their Connectra product: http://updates.checkpoint.com/files...katell.pdf
- hoolio
Cirrostratus
Hi Jon, - AJ_6093
Nimbostratus
Hi Aaron,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects