Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
226
Applications
213455-L, October 2005
User Authority
The User Authority feature in the Nortel Switched Firewall provides centralized management
of user authentication and authorization. User authority provides a unified, secure
communication layer for authenticating users to eBusiness applications.
It enables applications to make intelligent authorization decisions based on VPN-1/Firewall-1
authentication and security information.
The benefits of the user authority feature include:
Reduced sign-on burden
Fine-grained access control
Integration with security infrastructure
N
OTE
–
User authority is useful for web applications which run on Internet Information
Services (IIS) servers.
The user authority feature is used by two kinds of users:
LAN users
Users on the LAN use user authority to access the external resources to provide various
authentication and authorization facilities for each user level.
Remote users
Internet users use SR/SC or SSL to access various web applications on the web server in a
secure and reliable way using authentication and authorization mechanisms.
There are two kinds of remote users:
Mobile user with SecuRemote/SecureClient —authenticated by the VPN-1 Pro
gateway.
Mobile user without SecuRemote/SecureClient
—connects with SSL from any computer
—authenticated by the user authority web access.
To configure the Switched Firewall for user authority, perform the following:
1.
Configure the Switched Firewall with basic firewalling.
VPN connectivity should be established from the SecureRemote/SecureClient to the gateway
2.
Configure Check Point using SmartDashoard and its components.