Chapter 34 Object
ZyWALL ATP Series User’s Guide
651
3
The Zyxel Device requests the user’s user-name, password and mobile phone number or email address
from the Active Directory, RADIUS server or local Zyxel Device database in order to authenticate this
user's use of the VPN tunnel (factor 1). If they are not found, then the Zyxel Device terminates the VPN
tunnel.
4
If all correct credentials are found, then the Zyxel Device will request the Cloud SMS system to send an
authorization SMS or email to the client requesting VPN access (factor 2).
5
The client should access the authorization link sent via SMS or email by the Cloud SMS system within a
specified deadline (
Valid Time
).
6
If the authorization is correct and received on time, then the client can have VPN access to the secured
network. If the authorization deadline has expired, then the client will have to run the VPN client again. If
authorization credentials are incorrect or if the SMS/email was not received, then the client must check
with the network administrator.
Pre-configuration
Before configuration, you must:
• Set up the user’s user-name, password and email address or mobile number in the Active Directory,
RADIUS server or local Zyxel Device database
• Configure the VPN tunnel for this user on the Zyxel Device
• Have an account with ViaNett to be able to send SMS/email authorization requests
• Enable
HTTP
and/or
HTTPS
in
System > WWW > Service Control
• Configure
SMS
in
System > Notification > SMS.
• Add
HTTP
and/or
HTTPS
in the
Object > Service > Service Group > Default_Allow_WAN_To_ZyWALL
service group.
Two-Factor authentication may fail if one of the above is not configured or:
• The user did not receive the authorization SMS or email. Check if the mobile telephone number or
email address of the user in the Active Directory, RADIUS Server or local Zyxel Device database is
configured correctly
• ViaNett Authentication failed and no SMS was sent. Check that SMS is enabled and credentials are
correct in
System > Notification > SMS
.
• Mail server authentication failed. Check if the
System > Notification > Mail Server
settings are correct.
• The authorization timed out. Extend the Valid Time in
Configuration > Object > Auth. Method > Two-
factor Authentication
.
Configuration
Go to
Configuration > Object > Auth. Method > Two-factor Authentication
and configure the following
screen as shown.