![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
2 Factor Authenticationthis thread has 4 replies and has been viewed 588 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
I need to implement 2 factor authentication into my domain on all remote access connections.Does anyone have any recommendations on good systems / solutions?We currently use Citrix but are looking to also start using VPN clients on our laptops.
|
|
#2
|
||||||||||
|
||||||||||
|
RSA or Cryptocard is where I've positive experience with.
__________________
Marcel Netherlands http://www.phetios.com http://blog.nessus.nl MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE No matter how secure, there is always the human factor. |
|
#3
|
||||||||||
|
||||||||||
|
NAP under Server 2008 supports certifcate/smartcard authentication in association with PEAP as well.
|
|
#4
|
||||||||||
|
||||||||||
|
Do you have any investment in hardware already (fingerprint readers on laptops or smart card readers)? If so, this may help force your decision
Also ask yourself, what is the business case vs usernames and strong passwords?
__________________
Tom Jones MCT, MCSE (2000:Security & 2003), MCSA:Security & Messaging, MCDBA, MCDST, MCITP(EA, EMA, SA, EDA, ES, CS), MCTS, MCP, Sec+ PhD, MSc, FIAP, MIITT IT Trainer / Consultant Ossian Ltd Scotland ** Remember to give credit where credit is due and leave reputation points where appropriate ** |
|
#5
|
||||||||||
|
||||||||||
|
Remote access vpn's with cisco routers and ASA's support xauth (extended authentication)as part of phase 1.5. So the client authenticates the correct "vpn group" then also is prompted for user authentication. This authentication can be local, RADIUS, TACACS , Active Directory with pre-shared keys or certificates. They also support group-lock which will prevent a user from logging into another vpn group. You can also look at SSL vpn's, either clientless or client based with the cisco anyconnect client. SSL clientless is by far the easiest for the end user as no client is required. You can also setup portfowards, favorites, smart tunnels etc per group/user. Pretty much the ASA/router acts as a SSL proxy.
__________________
CCNA, CCNA-Security, CCNP CCIE Security (In Progress) Last edited by auglan; 6th August 2012 at 15:14.. |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Would Half-Duplex factor into EIGRP route selection? | caleban | Cisco Routers & Switches How-to | 2 | 14th November 2009 06:33 |
| ISA and Authentication | outstream | General Security | 8 | 18th July 2009 14:25 |
| Forms Based Authentication and Windows Integrated Authentication | bworchel | Exchange 2000 / 2003 | 2 | 27th February 2009 02:12 |
| 2-factor authentication for MS Terminal Services | JacoP | General Security | 10 | 15th June 2008 07:42 |
| DC authentication | tatasys | Active Directory | 19 | 11th August 2005 18:00 |