Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
This article describes how to enable Nexus OTP in Nexus Hybrid Access Gateway as two-factor authentication method for SafeInspect, to replace static passwords.
Nexus OTP can be either Nexus TruID Synchronized or Nexus Personal Mobile OTP, or any other OATH-based mobile OTP application, such as Google Authenticator or Microsoft Authenticator.
With the setup described in this article, Nexus Hybrid Access Gateway functions as a RADIUS server and SafeInspect as a RADIUS client. Nexus TruID is used as an example below and is available for iOS, Android, and Windows.
title | Network schematic for Nexus OTP authentication |
---|
Image Removed
Network schematic with Nexus TruID Synchronized as an example.
- The end user starts the TruID client and enters the PIN in TruID to generate an OTP.
- Cyberoam request the end user to enter username, password and OTP.
- The end user enters username, domain password and OTP.
- The domain credentials are validated by the Active Directory.
- The OTP authentication request is relayed to Hybrid Access Gateway Authentication Server via RADIUS.
- The authentication server validates the OTP with the associated TruID token and PIN from the user database.
- Upon successful validation, the authentication server responds with successful authentication to Cyberoam.
Cyberoam provides access to the end user.
Prerequisites
Expand | ||
---|---|---|
| ||
|
Make settings in Hybrid Access Gateway
Expand | ||
---|---|---|
| ||
|
Expand | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||
|
Expand | ||||||
---|---|---|---|---|---|---|
| ||||||
Nexus TruID Synchronized Personal Mobile is used as an example. Other Nexus OTP authentication methods are enabled in a similar way.
| Set up authentication method | Set up authentication method | nopanel | true, see Set up Personal authentication.
Make settings in SafeInspect
Expand | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||||
|
Example: Log in to SafeInspect
The following example shows how an end user logs in, using Nexus Personal Mobile. Other Nexus OTP methods can be used in a similar way.
Expand | ||
---|---|---|
| ||
|