- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Is there a way to use two-factor authenticatio...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to use two-factor authentication for SmartConsole and Gaia Web portal/SSH console?
Is there a way to use two-factor authentication for SmartDashboard and Gaia Web portal/SSH console?
Some combination like cert+username/password or with Radius supporting OTP (One time passwords).
We have audit recommendations that all devices that manage access to PCI DSS network segments should have two-factor authentication.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can authenticate to SmartConsole with a certificate:
You can also define certificates for users as well (if both password and certificate are defined, both credentials are required to log in):
For the WebUI on Gaia OS, certificates cannot be used, but you can use a RADIUS/TACACS+ server that requires a one-time password for authentication.
Note that RADIUS/TACACS+ is also supported for SmartConsole authentication as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Dameon!
I am aware of using certificates and password, but during my tests I was able to login only with one of the methods - password or certificate, no both of them.
Will try to build a test setup with RADIUS and OTP also. I am wondering is there a feature to display field for entering the OTP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is only one field for entering a password, unfortunately.
If you want BOTH an OTP and a regular password, you may be able to set that up on the RADIUS server (similar to how SecurID does it).
