Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This article describes how to enable Nexus OTP

in Nexus Hybrid Access Gateway as

in Smart ID Digital Access component as two-factor authentication method for SafeInspect, to replace static passwords.

Nexus OTP can be either Nexus TruID Synchronized or 

Nexus Personal

Smart ID Mobile App OTP, or any other OATH-based mobile OTP application, such as Google Authenticator or Microsoft Authenticator. 

With the setup described in this article,

Nexus Hybrid

Digital Access

Gateway

functions as a RADIUS server

and SafeInspect

and SafeInspect as a RADIUS client. Nexus TruID is used as an example below and

is available

is available for iOS, Android, and Windows

. Expand
titleNetwork schematic for Nexus OTP authentication

Image Removed

Network schematic with Nexus TruID Synchronized as an example.

  1. The end user starts the TruID client and enters the PIN in TruID to generate an OTP.
  2. Cyberoam request the end user to enter username, password and OTP.
  3. The end user enters username, domain password and OTP.
  4. The domain credentials are validated by the Active Directory.
  5. The OTP authentication request is relayed to Hybrid Access Gateway Authentication Server via RADIUS.
  6. The authentication server validates the OTP with the associated TruID token and PIN from the user database.
  7. Upon successful validation, the authentication server responds with successful authentication to Cyberoam.
Cyberoam provides access to the end user

.

Prerequisites

Expand
titlePrerequisites
Installed and deployed Hybrid Access Gateway, see Deploy Hybrid Access Gateway and do initial setup

Make settings

in Hybrid

in Digital Access

Gateway

Expand
titleLog in to

Hybrid
Digital Access
Gateway administration interface
Admin
  1. Log in to
the Hybrid Access Gateway administration interface with your admin user
  1. Digital Access Admin with an administrator account.


Expand
titleAdd SafeInspect as a RADIUS client


Note
In step 3, enter the IP Address of the RADIUS Client (SafeInspect) and the Shared Secret Key.

Insert excerpt
Set up RADIUS client in Digital Access
Set up RADIUS client in Digital Access
nopaneltrue


Expand
titleEnable authentication method
Nexus TruID Synchronized

Smart ID Mobile App is used as an example

. Other Nexus OTP authentication methods are enabled in a similar way.
Note
  • In step 3, select Nexus Synchronized as method.
  • When the default RADIUS replies are shown, click Next. You can also add your custom RADIUS replies or modify the default replies if required.
Insert excerptSet up authentication methodSet up authentication methodnopaneltrue

, see Set up Smart ID authentication.

Make settings in SafeInspect

Expand
titleAdd
Hybrid
Digital Access
Gateway
as RADIUS Server
  1. Log in to the SafeInspect administrative interface.
  2. Navigate to Identity > External Authentication > RADIUS Servers.

  3. Click Add RADIUS server and go to the Settings tab.

    Image Modified

  4. Enter the following information:

    ParameterDescription
    AddressEnter the IP address of the
Hybrid
  1. Digital Access
Gateway
  1. Authentication server
    Port

    Select the port of

the Hybrid
  1. the Digital Access

Gateway
  1. Authentication server for the particular authentication method

    Shared secretEnter the RADIUS shared secret key
    Shared secret confirmationConfirm the RADIUS shared secret key


  2. Go to the Policy tab.

  3. Add an authentication rule with the following settings:

    ParameterDescription
    Client-to-Hound authenticationSelect: Authenticate against a RADIUS server
    RADIUS server

    Select the IP address and port of

the Hybrid
  1. the Digital Access

Gateway
  1. Authentication server

    Hound-to-target authentication

    Select: Mapped user credentials


Example: Log in to SafeInspect

The following example shows how an end user logs in, using

Nexus Personal Mobile. Other Nexus OTP methods can be used in a similar way. 

Smart ID Mobile App.



Expand
titleUse
Nexus TruID
Smart ID Mobile App as 2FA to log in to
CyberoamStart Nexus TruID
SafeInspect
  1. Start Smart ID Mobile App that is installed on your laptop or smartphone - Enter your PIN to generate an OTP.

Image RemovedImage RemovedEnter Key-In domain login id and password along with Nexus TruID OTP.
Image Removed