Page 2 - Solution Summary; Partner Integration Overview
Solution Summary The Nortel Networks VPN Gateway 3050 is a remote access security solution that extends the reach of enterprise applications and resources to remote employees, partners, and customers. By using the native capability of widely deployed Web browsers, the SSL VPN Gateway offers a conven...
Page 3 - Product Requirements; Partner Product Requirements: Nortel VPN Gateway 3050; RSA SecurID files; RSA SecurID Authentication Files
Product Requirements Partner Product Requirements: Nortel VPN Gateway 3050 Firmware Version 7.0.1.0 Hardware Platform Platform Required Patches VPN 3050, ASA 310, ASA 410, ASA 310 FIPS N/A Additional Software Requirements Application Additional Patches Internet Explorer 5.0, 5.5 and 6.0 RSA SecurID ...
Page 4 - Agent Host Configuration
Agent Host Configuration Important: “Agent Host” and “Authentication Agent” are synonymous. “Agent Host” is a term used with the RSA Authentication Manager 6.x servers and below. RSA Authentication Manager 7.1 uses the term “Authentication Agent”. Important: All “Authentication Agent” types for 7.1 ...
Page 5 - Partner Authentication Agent Configuration; Before You Begin; RSA SecurID Authentication Configuration Overview
Partner Authentication Agent Configuration Before You Begin This section provides instructions for integrating the partners’ product with RSA SecurID Authentication. This document is not intended to suggest optimum installations or configurations. It is assumed that the reader has both working knowl...
Page 6 - Creating and Configuring a RSA SecurID or RADIUS User Group
Creating and Configuring a RSA SecurID or RADIUS User Group 1. From the admin console, expand VPN Gateways and click Add to add a VPN Gateway. 2. Click Create VPN . 3. Now click on the VPN Gateway you just created and click on Groups . 4. Click on the button Add New Group . 5. Fill out the form with...
Page 8 - Configuring the RADIUS Authentication Servers
Configuring the RADIUS Authentication Servers 6. From the admin console, select VPN Gateways > Authentication . 7. Click Add . 8. Enter information for the Authentication Server such as Name and Display Name. The Authentication Mechanism will be RADIUS . Then click update to complete additional R...
Page 10 - Testing the configuration
Testing the configuration 1. Open a web browser and point to the portal address. 2. For user credentials enter a SecurID username and Passcode. 3. From the Login Service list select your RSA SecurID or RSA RADIUS challenge group. 4. Click Login to authenticate and enter the Portal Server. Note: The ...
Page 11 - Certification Checklist
Certification Checklist Date Tested: September 26, 2007 Certification Environment Product Name Version Information Operating System RSA Authentication Manager 6.1 Windows 2003 Server RSA RADIUS Server 6.1 Windows 2003 Server VPN Gateway 3050 7.0.1.0 IOS Router Mandatory Functionality RSA Native Prot...
Page 13 - Known Issues
Known Issues PIN Rejection: When a PIN is rejected by the Authentication Manager Server the user is questioned by the client to try a different PIN but the program flow is not intuitive. 1. The user first authenticates using either Token or Password. The user is next prompted to create a new PIN. 2....
Page 14 - Administration Logon.
Administration Logon. NEW-PIN mode does not work via the admin console. The user is prompted to create or accept a PIN but the PIN never gets sent to the server and the user gets redirected to a blank web page. 14
Page 15 - Appendix; Delete Node Secret
Appendix Delete Node Secret 1. Navigate to Config > Administration > RSA Servers and click on the link for the RSA Authentication Server Label you created. 2. Click the button labeled Remove Node Secret . Remove sdconf.rec and sdstatus.12 1. Navigate to Config > Administration > RSA Serv...