•
HTTPS traffic
•
IPsec tunnel traffic
•
L2TP tunnel traffic
•
PPTP tunnel traffic
•
SSL VPN tunnel traffic
3.
If no rule matches, the connection is allowed, provided the IP rule set permits it, and
nothing further happens in the authentication process.
4.
Based on the settings of the first matching authentication rule, NetDefendOS may prompt
the user with an authentication request which requires a username/password pair to be
entered.
5.
NetDefendOS validates the user credentials against the
Authentication Source
specified in
the authentication rule. This will be either a local NetDefendOS database, an external
RADIUS database server or an external LDAP server.
6.
NetDefendOS then allows further traffic through this connection as long as authentication
was successful and the service requested is allowed by a rule in the IP rule set. That rule's
Source Network object has either the No Defined Credentials option enabled or
alternatively it is associated with a group and the user is also a member of that group.
7.
If a timeout restriction is specified in the authentication rule then the authenticated user will
be automatically logged out after that length of time without activity.
Any packets from an IP address that fails authentication are discarded.
8.2.7. HTTP Authentication
Where users are communicating through a web browser using the HTTP or HTTPS protocol then
authentication is done by NetDefendOS presenting the user with HTML pages to retrieve
required user information. This is sometimes also referred to as
WebAuth
and the setup requires
further considerations.
The Management Web Interface Port Must Be Changed
HTTP authentication will collide with the Web Interface's remote management service which also
uses TCP port 80 by default. To avoid this problem, the Web Interface port number must be
changed before configuring authentication.
Do this by going to Remote Management > Advanced settings in the Web Interface and
changing the setting WebUI HTTP Port. Port number 81 could instead, be used for this setting.
The same is true for HTTPS authentication and the default HTTPS management port number of
443 must also be changed.
HTTP and HTTPS Agent Options
For HTTP and HTTPS authentication there is a set of options in an authentication rule called
Agent Options. These are:
•
Login Type - This can be one of:
Chapter 8: User Authentication
627
Summary of Contents for NetDefendOS
Page 30: ...Figure 1 3 Packet Flow Schematic Part III Chapter 1 NetDefendOS Overview 30 ...
Page 32: ...Chapter 1 NetDefendOS Overview 32 ...
Page 144: ...Chapter 2 Management and Maintenance 144 ...
Page 284: ...Chapter 3 Fundamentals 284 ...
Page 392: ...Chapter 4 Routing 392 ...
Page 419: ... Host 2001 DB8 1 MAC 00 90 12 13 14 15 5 Click OK Chapter 5 DHCP Services 419 ...
Page 420: ...Chapter 5 DHCP Services 420 ...
Page 573: ...Chapter 6 Security Mechanisms 573 ...
Page 607: ...Chapter 7 Address Translation 607 ...
Page 666: ...Chapter 8 User Authentication 666 ...
Page 775: ...Chapter 9 VPN 775 ...
Page 819: ...Chapter 10 Traffic Management 819 ...
Page 842: ...Chapter 11 High Availability 842 ...
Page 866: ...Default Enabled Chapter 13 Advanced Settings 866 ...
Page 879: ...Chapter 13 Advanced Settings 879 ...