Sophos Firewall - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide
This article describes how to integrate Sophos Firewall with RSA Authentication Manager using RADIUS.
Configure RSA Authentication Manager
Perform these steps to configure RSA Authentication Manager using RADIUS.
Procedure
- Sign in to Security Console.
- Navigate to RADIUS > RADIUS Servers and make a note of the IP address of the selected RADIUS server. This will be later used in the Sophos Firewall configuration.
- Navigate to RADIUS > RADIUS Clients and click Add New.
- On the Add RADIUS Client page, enter the following details:
- Client Name: Enter a descriptive name for the RADIUS client.
- IPv4 Address: Enter the IP address of the RADIUS client (IP address of Sophos Firewall).
- Make/Model: Select Standard Radius in the drop-down list.
- Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the RADIUS client and the RADIUS server.
- Click Save & Create Associated RSA Agent.
- On the Add New Authentication Agent page, click Save, and then confirm by clicking Yes, Save Agent.
Notes
- RSA Authentication Manager RADIUS server listens on ports UDP 1645 and UDP 1812.
- The relationship of agent host record to RADIUS client in the Authentication Manager can be 1 to 1, 1 to many, or 1 to all (global).
- Shared Secret must be an alphanumeric string between 1 and 31 characters in length and is case-sensitive.
Configure Sophos Firewall
Perform these steps to configure Sophos Firewall as a RADIUS client to RSA Authentication Manager.
Procedure
- Log in to the Admin portal of Sophos Firewall.
- In the left pane, select Authentication.
- On the Authentication tab, choose Add to add a new RADIUS authentication server.
- On the Add external server screen, fill in the required details:
- Server type: Choose RADIUS server in the drop-down list.
- Server name: Choose a name for the RADIUS server.
- Server IP: The IP address of the RADIUS server. This should be the IP of the RADIUS server on RSA Authentication Manager.
- Time-out: Increase the timeout to 15 seconds.
- Shared secret: Choose the same secret as the one configured earlier in RSA.
- Group name attribute: This field specifies which RADIUS attribute Sophos should read to determine the user’s group membership. It allows dynamic user-to-group mapping based on RADIUS responses. This helps apply that group’s access controls, time policies, and bandwidth.
- Click Test connection.
- Once the test is successful, click Save.
- Under Authentication, navigate to the Services tab.
- Depending on your organization’s specific use case, edit the Authentication methods to include the newly created RADIUS server from the Authentication Server list under Selected authentication server. You can change the priority of the authentication methods by reordering them in the list.
- To configure Sophos Firewall for SSL VPN usage, an SSL VPN policy should be created to control remote VPN connections, the resources they are allowed to access, and how they will be authenticated to the VPN.
To configure SSL VPN:- In the left pane, select Remote access VPN.
- Click the SSL VPN tab and click Add.
- Follow the instructions provided on the screen for your preferred configurations and access restrictions. In Step 3, choose your desired users or groups that will be allowed to connect to the VPN and hence authenticate with RSA.
- In Step 4, Authentication servers (global setting), choose the configured RSA RADIUS server as the method for authentication for the SSL VPN by clicking the Set authentication method for SSL VPN radio button, and click Next.
- Complete the rest of the steps, review the settings, and click Finish. Your SSL VPN is ready now for use, authenticating via RADIUS with RSA.
The configuration is complete.
Related Articles
FortiGate Firewall - Configure RADIUS Authentication Manager Using SSL VPN - RSA Ready Implementation Guide 100Number of Views XUDATIMEOUT and Checkpoint firewall issue 22Number of Views RSA Via Lifecycle and Governance - How to set up an environment to run WebServices with Turkish Characters 12Number of Views Remote Access VPN Configuration - Cisco FTD RSA Ready SecurID Access Implementation Guide 45Number of Views Configuring a Checkpoint firewall to work with SecurID 324Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes for RSA Authentication Manager 8.8 Deploying RSA Authenticator 6.2.2 for Windows Using DISM Downloading RSA Authentication Manager license files or RSA Software token seed records
Don't see what you're looking for?