- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Enabling 2 Factor for specific user group
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Enabling 2 Factor for specific user group
Hi, Currently we are maintaining local users to log in to Remote VPN client, customer wants to enable two factor (Dynamic ID with third party SMS provider) for specific users only. Is it possible to enable for specific user group with dynamic ID?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had been wondering exact same thing for a while now, so Im glad you posted this question...lets see if we can get a confirmation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You select the login scheme before entering the username, so it's not possible to configure different login schemes for different groups.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is my understanding as well, the scope of DynamicID is the gateway or cluster object, not user or groups.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can use multiple authentication settings per gateway. Edit the gateway or cluster object, VPN Clients, Authentication, "multiple authentication client settings", create profiles for the different authentication factors.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct, however OP wants to do different authentication schemes per user / group. For example Group A - Username & Password, Group B - Username & Password + SecureID.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can change the authentication profile during site creation or afterwards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The point is the GW to force me to use this profile based on my user/group, not what I configured when creating the site.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OP didn't mention anything about the gateway enforcing this. He just wants to enable DynamicID for specific users. This is possible by changing the site for those users and then setting "predefined_sites_only" to true via the gateways ttm file.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What if you use SNX?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
and how will you set profile 1 to be for user group1 and profile2 for group2?
