For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Harry1's avatar
Harry1
Icon for Nimbostratus rankNimbostratus
May 31, 2016

Want to understand about pre-requisites and flow for Bigip APM browser based sslvpn with RSA smart card and token

Dear Friends,

 

I just wanted to understand about ssl vpn(only browser based) with RSA.what could be the flow and pre-requisites in this case? first authentication method would be Active directory and second would be RSA.

 

appreciate any help or reply.

 

Regards

 

Prak

 

7 Replies

    • Harry1's avatar
      Harry1
      Icon for Nimbostratus rankNimbostratus
      Thanks Yann, actually i was also looking this same manual. i just wanted to draw a flowchart or steps that when external user will hit the vpn fqdn then what will be the flow ?
    • Harry1's avatar
      Harry1
      Icon for Nimbostratus rankNimbostratus
      as per my understanding, we can configure both dual factor as per requirement. i mean either we can enforce first authentication as a secure auth and second would be AD as per customer requirement or vice-versa . please correct if i am wrong.
    • Harry1's avatar
      Harry1
      Icon for Nimbostratus rankNimbostratus
      Thanks Yann, actually i was also looking this same manual. i just wanted to draw a flowchart or steps that when external user will hit the vpn fqdn then what will be the flow ?
    • Harry1's avatar
      Harry1
      Icon for Nimbostratus rankNimbostratus
      as per my understanding, we can configure both dual factor as per requirement. i mean either we can enforce first authentication as a secure auth and second would be AD as per customer requirement or vice-versa . please correct if i am wrong.
  • You can process the flow anyway you like. You can have AD first, RSA second or RSA first and AD Second. You can have different logon pages per authenticator if you like. It is totally up to you. The one thing you need to keep in mind is that the AAA objects will only use

    session.logon.last.password
    and
    session.logon.last.username
    so you have to do variables assigns as needed.

    Seth