How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the...

16
NSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic Edge One Time Password Server version 3 Cisco ASA 5500 serie Situation Nordic Edge One Time Password Server and the Cisco ASA 5500 serie have comprehensive RADIUS support and different two-factor authentication methods can be used to protect access to ressources OTPServer is protecting. Users may be given a choice when connecting to an SSL-VPN solution to receive a One Time Password via SMS, eMail or use the Nordic Edge Pledge client for mobile devices. This guide is describing how to setup a Cisco ASA 5500 serie and a Nordic Edge One Time Password server to offer Users two different OTP methods, SMS and Pledge. Solution ASA Configuration 1. Create two RADIUS groups, one for PLEDGE and one for SMS from ASA Device Manager Configuration/ Remote Access VPN/AAA/Local Users/AAA Server Groups + Add For example: - SMS

Transcript of How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the...

Page 1: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

NSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods

Fact

Nordic Edge One Time Password Server version 3

Cisco ASA 5500 serie

Situation

Nordic Edge One Time Password Server and the Cisco ASA 5500 serie have comprehensive RADIUS

support and different two-factor authentication methods can be used to protect access to ressources

OTPServer is protecting.

Users may be given a choice when connecting to an SSL-VPN solution to receive a One Time Password

via SMS, eMail or use the Nordic Edge Pledge client for mobile devices.

This guide is describing how to setup a Cisco ASA 5500 serie and a Nordic Edge One Time Password

server to offer Users two different OTP methods, SMS and Pledge.

Solution

ASA Configuration

1. Create two RADIUS groups, one for PLEDGE and one for SMS from ASA Device Manager Configuration/

Remote Access VPN/AAA/Local Users/AAA Server Groups + Add

For example:

- SMS

Page 2: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

- PLEDGE

Page 3: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

2. For each RADIUS group, configure a RADIUS server with same IP address but different port numbers.

- Click on Add from "Servers in Selected Group"

- Configure NORDIC-EDGE-SMS with port 1645

Page 4: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

- Configure NORDIC-PLEDGE with port 1812

Page 5: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

3) Create a CONNECTION-PROFILE (also called tunnel-groups) for each method, one for SMS and one for PLEDGE.

Associate these profiles to their respective Radius server group (Step 1).

- Create OTP-NORDIC-EDGE connection profile, use alias "OTP SMS" and choose corresponding AAA Server Group

(NORDIC-EDGE-SMS) created in step 1.

Page 6: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

- Create NORDIC-PLEDGE connection profile, use alias "PLEDGE" and choose corresponding AAA Server Group

(NORDIC-PLEDGE) created in step 1.

Page 7: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

4. Verify that option "Allow user to select connection profile, identified by its alias, on the login page." from configuration screen below is checked. It is found under global connection profiles, Configuration/Remote Access VPN/Clientless SSL VPN Access.

Page 8: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

5. Users should now be able to choose a Group from the Drop Down list corresponding to the the login method they would like to use.

OTPServer Configuration  To match above ASA setup: Add additional port 1812 in the Radius Section

Page 9: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Configure two Radius Clients corresponding to ASA Radius Groups For example: Cisco- SMS

Page 10: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Click the Advanced button and Un-check Option Listen on All Available Port Numbers.

Page 11: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Then Select Radius Port 1645 and Click OK

Page 12: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Cisco-Pledge

Page 13: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Click the Advanced button and Un-check Option Listen on All Available Port Numbers.

Page 14: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Then Select Radius Port 1812 and Click OK

Page 15: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

Verify configuration in OTPServer Radius section by entering 1645 as an Additional Port 

Page 16: How to set up the Cisco Networks ASA 5500 SSL-VPN Edition · PDF fileNSD1237 How to Setup the Cisco Networks ASA 5500 SSL-VPN Edition to Use Different OTPServer Methods Fact Nordic

OTPServer will now listen to ASA Group  Note: Port 1645 will NOT be saved as an Additional Port.