Configure the External Authentication Server
Some of the features described in this section are only available to participants in the WatchGuard Beta program. If a feature described in this section is not available in your version of Fireware, it is a beta-only feature.
Active Directory — Users must belong to an Active Directory security group with the same name as the group name you configure for Mobile VPN with SSL.
RADIUS, VASCO, or SecurID — Make sure that the RADIUS server sends a Filter-Id attribute (RADIUS attribute 11) when a user successfully authenticates, to tell the Firebox what group the user belongs to. The value for the Filter-Id attribute must match the name of the Mobile VPN group as it appears in the Fireware RADIUS authentication server settings. All Mobile VPN users that authenticate to the server must belong to this group.
AuthPoint — In Fireware v12.7 or higher, you can select AuthPoint as an authentication server in the Mobile VPN with SSL configuration. The group and user names you specify in the Mobile VPN with SSL configuration must match the group and user names that you specify in AuthPoint.