Cisco PIX 525 Especificaciones Pagina 406

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 466
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 405
B-2
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Appendix B Configuration Examples for Other Remote Access Clients
Xauth with RSA Ace/Server and RSA SecurID
Token co de: The code displayed by the token. The tokencode along with the PIN make up the RSA
SecurID authentication system.
PIN: The user’s personal identification number.
Two-Factor authentication: The authentication method used by the RSA ACE/Server system in which
the user enters a secret PIN (personal identification number) and the current code generated by the user’s
assigned SecurID token.
PASSCODE: The PIN and the tokencode make up the PASSCODE.
Token Mode: The state the token is in. The token can be Enabled, Disabled, or be in the New PIN Mode,
Next Tokencode Mode.
New PIN mode: When the server puts a token in this mode, the user is required to receive or create a
new PIN to gain access to an RSA SecurID-protected system.
Next Tokencode mode: When the user attempts authentication with a series of incorrect PASSCODEs,
the server puts the token in this mode so that the user, after finally entering the correct code, is prompted
for another tokencode before being allowed access.
Pinpads: A SecurID hardware token that allows entering the PIN via a Pinpad and displays the
tokencode in an LCD display.
Key Fobs: Another form of SecurID hardware token, that displays the current tokencode.
Software Token: A software token is similar to the Pinpad, which can be installed on the user’s machine.
Introduction
The RSA Ace/Server and RSA SecurID combination can be used to provide authentication for the
Cisco
VPN Client Version 3.x, the Cisco VPN 3000 Client Version 2.5, and the
Cisco
Secure VPN Client Version 1.1, which are supported by PIX Firewall. SecurID provides a
token-based authentication method in the form of Software Tokens, Pinpads, or Key Fobs. The user is
assigned a token and uses that value from the token, called the tokencode, for authentication. A PIN is
used along with the tokencode to obtain the Passcode.
The different modes that a token can use are:
Enabled.
Next Tokencode mode.
New PIN mode.
The PIN length and type are as defined in the system parameters of the ACE/Server, and some parameters
can also be set on a per-user basis. When a token is assigned, it is enabled and is in a New PIN mode.
The PIN could be pre-assigned, or the RSA ACE/Server configuration can decide who can create that
PIN. The options for PINs are as follows:
User-created PINs allowed
User-created PINs required
These options can also be decided on a per-user basis by selecting the appropriate check box on the Edit
User panel provided by the ACE/Server master database administration tool.
The “User-created PINs allowed” option provides a choice between the system generating the PIN, and
then providing it to the user, or the user selecting the PIN.
The “User-created PINs required” option requires the user to select the PIN.
Vista de pagina 405
1 2 ... 401 402 403 404 405 406 407 408 409 410 411 ... 465 466

Comentarios a estos manuales

Sin comentarios