The appliance supports two different types of credentials for RADIUS: username and password, and token-based user credentials, such as SecurID or SoftID, which are validated against a database on a RADIUS server. You can configure the RADIUS authentication method to use either type of credential.
You can also deploy PhoneFactor authentication using RADIUS. When a user logs into their company’s VPN, a RADIUS request is made to the PhoneFactor Agent, which acts as a RADIUS proxy server. It first validates the user name and password with the target RADIUS server before initiating a PhoneFactor authentication. There are two methods for two-factor authentication using PhoneFactor:
The user enters his username and password and is then called by PhoneFactor. The user answers his phone and presses # or enters a PIN.
The user enters his username and password and then PhoneFactor sends him a text message containing a one-time passcode. The user replies to the text message with the passcode, or the passcode and his PIN, to authenticate.
To configure RADIUS for user- or token-based credentials
In the AMC, navigate to System Configuration > Authentication Servers.
Click New.
Click RADIUS.
In the Name field, type a name for the authentication server.
:<port number>).In the Match RADIUS groups by list, select the attribute containing the groups of which the user is a member. The value returned from RADIUS will be used in the group portion of the appliance access rule. There are three possible values:
| Match RADIUS groups by | Description |
| None | Ignores the group attribute |
| filterid attribute (11) | Matches against the FilterID attribute |
| class attribute (25) | Matches against the Class attribute |
Click Save.