This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Community Blog

Subscribe to the official SecurID Community blog for information about new product features, industry insights, best practices and more.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Blogs
  • :
  • Protect Stormshield VPN with RSA MFA

Protect Stormshield VPN with RSA MFA

AngeOAmbemou
Occasional Contributor AngeOAmbemou Occasional Contributor
Occasional Contributor
3 6 2,439
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
‎2020-10-22 09:24 AM

Stormshield network security is a strong UTM help customer protect infrastructures. This firewall offers ipsec and SSL VPN for end user.

In this blog i show you how integrate Stormshield with IDR to protect user remote access.

 

Let's go 

 

Stormshield supports radius for integration with Authentication manager or Identity Router. 

 

 

Stomshield  configuration

 

At Stormshield level you need to configure the radius server (your IDR or AM) and your share secret.

 

pastedImage_18.png

 

Define radius at anthentication policy

 

pastedImage_19.png

 

IDR Configuration 

At CAS i define my radius client 

 

pastedImage_27.png

And ask to the cloud to validate only the policy. Because of timeout issue at Stormshield level i can used only RSA Securid Authenticate app authenticate Tokencode.

 

For security purpose add a PIN or Device Biometrics to view the Authenticate Tokencode at CAS level.

 

pastedImage_28.png

 

After this push your policies and you are ready to authenticate.

 

pastedImage_29.png

 

At password unlock your RSA Securid Authenticate app and enter the tokencode to access the VPN 

pastedImage_36.png

pastedImage_34.png

 

Caution 

 

1 - In the integration with Authentication Manager, Stormshield not support PIN Creation, we need to used self service console to initate the PIN or used another protected ressource (laptop with RSA agent for window for example).

 

2 - If you want to used VPN client is better to use Openvpn client inside of Stormshield VPN client, Stormshield vpn client sends 2 times the same authentication request is like replay attack at AM/IDR side.

 

3 -  Timeout issue:  at the time i write this blog there are no way to modify Stormshield timeout radius  in UI or CLI.

 

Tags (5)
  • Tags:
  • integration brief
  • RSA SecurID
  • rsa securid acces
  • RSA SecurID Access
  • SecurID
3 Likes
Share
6 Comments

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • In the era of Hybrid Work – SecurID macOS Authenticator is here!
  • SecurID Cloud Authentication Service Transitions Identity Source Synchronization from Scheduled Sync...
  • SecurID JUNE Release Accelerates RSA Cloud First Strategy
  • Introducing the New SecurID™ App 3.0 for iOS® and Android™
  • Stronger, Simpler and Better – 3 Reasons on choosing SecurID® for Passwordless Windows log-in
  • Defense-in-Depth: RSA SecurID® Access in November 2020
  • Protect Stormshield VPN with RSA MFA
  • Optimize your Dynamic Workforce with RSA SecurID Access
  • Securing access to corporate endpoints is made easy with RSA MFA Agent 2.0.1 for Microsoft Windows
  • New RSA SecurID Access & Authentication Manager Training – Your commute hours have never been so pro...
Labels
  • Announcements 3
  • Features 1
  • Resources 1
  • Tutorials 27
  • Use Cases 3
  • Videos 93
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.