Configure the External Authentication Server
If you create a Mobile VPN user group that authenticates to a third-party server, make sure you create a group on the server that has the same name as the name you added in the wizard for the Mobile VPN group.
If you use Active Directory as your authentication server, the users must belong to an Active Directory security group with the same name as the group name you configure for Mobile VPN with IPSec.
You must use the WatchGuard IPSec Mobile VPN Client if you want to use Vasco RADIUS or RSA SecurID authentication servers.