Configure the External Authentication Server

If you create a Mobile VPN user group that authenticates to a third-party server, make sure you create a group on the server that has the same name as the name you added for the Mobile VPN group.

If you use Active Directory as your authentication server, the users must belong to an Active Directory security group with the same name as the group name you configure for Mobile VPN with SSL.

For RADIUS, VASCO, or SecurID, make sure that the RADIUS server sends a Filter-Id attribute (RADIUS attribute 11) when a user successfully authenticates, to tell the XTM device what group the user belongs to. The value for the Filter-Id attribute must match the name of the Mobile VPN group as it appears in the Fireware XTM RADIUS authentication server settings. All Mobile VPN users that authenticate to the server must belong to this group.

See Also

About Third-Party Authentication Servers

Give Us Feedback  •   Get Support  •   All Product Documentation  •   Knowledge Base