Forum Discussion
Want to understand about pre-requisites and flow for Bigip APM browser based sslvpn with RSA smart card and token
Dear Friends,
I just wanted to understand about ssl vpn(only browser based) with RSA.what could be the flow and pre-requisites in this case? first authentication method would be Active directory and second would be RSA.
appreciate any help or reply.
Regards
Prak
7 Replies
- Yann_Desmarest_
Nacreous
Hi,
In terms of pure security, I would recommend to set a login page with 3 fields (username, password, 2-factor) and authenticate first for the RSA token (using RSA native AAA or Radius Auth), then if 2-factor auth is successful, do the AD authentication.
In terms of configuration, you can use the following as an example :
- Harry1
Nimbostratus
Thanks Yann, actually i was also looking this same manual. i just wanted to draw a flowchart or steps that when external user will hit the vpn fqdn then what will be the flow ? - Harry1
Nimbostratus
as per my understanding, we can configure both dual factor as per requirement. i mean either we can enforce first authentication as a secure auth and second would be AD as per customer requirement or vice-versa . please correct if i am wrong.
Hi,
In terms of pure security, I would recommend to set a login page with 3 fields (username, password, 2-factor) and authenticate first for the RSA token (using RSA native AAA or Radius Auth), then if 2-factor auth is successful, do the AD authentication.
In terms of configuration, you can use the following as an example :
- Harry1
Nimbostratus
Thanks Yann, actually i was also looking this same manual. i just wanted to draw a flowchart or steps that when external user will hit the vpn fqdn then what will be the flow ? - Harry1
Nimbostratus
as per my understanding, we can configure both dual factor as per requirement. i mean either we can enforce first authentication as a secure auth and second would be AD as per customer requirement or vice-versa . please correct if i am wrong.
- Seth_Cooper
Employee
You can process the flow anyway you like. You can have AD first, RSA second or RSA first and AD Second. You can have different logon pages per authenticator if you like. It is totally up to you. The one thing you need to keep in mind is that the AAA objects will only use
andsession.logon.last.password
so you have to do variables assigns as needed.session.logon.last.usernameSeth
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com