Installation Guide
9.2 Browse to Configuration, Remote Access VPN, AAA/Local Users, AAA Server Groups
and click Add. ...................................................................................................................................... 33
9.3 Name Server Group OTPserver, choose protocol RADIUS ................................................ 34
9.4 Add new radius server to the RADIUS group ....................................................................... 35
9.5 Configure Radius Server : Interface name, IP address to OTPserver and the pre-shared
key between the One Time Password server and Cisco ASA5500. ............................................... 35
9.6 Create a ”test” connection profile (in case you want to test this for certain users only).
37
9.6.1 Browse to Configuration/Remote Access/Clientless SSL VPN Access/Connection Profiles
and click Add..................................................................................................................................... 37
9.6.2 Specify Connection Profile Name...................................................................................... 38
9.6.3 Specify AAA Server Group = OTPserver ......................................................................... 38
9.6.4 Edit Connection Profile Clientless SSL VPN Settings....................................................... 40
9.6.5 Add Alias if user should be able to select authentication method by drop-down-list ........ 40
9.6.6 Edit Connection Profile Clientless SSL VPN Settings....................................................... 41
9.6.7 Add Group URL if user should be able to select authentication by specifying URL ......... 41
9.6.8 If user should be allowed to select authentication method by drop-down-list,.................. 41
9.6.9 select this item................................................................................................................... 41
10 CONFIGURING ASA5500 FOR CISCO VPN CLIENT AUTHENTICATION WITH NORDIC
EDGE OTP SERVER ............................................................................................................................ 45
10.1 Add a new ( or Edit an existing) Cisco VPN Client Connection Profile to use the
OTPserver............................................................................................................................................. 45
10.2 At the Cisco VPN Client, create an entry with correct name and password ..................... 46
Name must match the connection profile name at previous slide......................................... 46
Password must match the pre-shared key in ASA5500. ......................................................... 46
(Note : This can be distributed via MSI installation)........................................................................ 46
11 START TESTING ...................................................................................................................... 47
11.1 Enter your Userid and password as usual............................................................................ 47
11.2 You will receive a one-time password to your mobile phone within a couple of seconds.
47
11.3 Enter your one time password and click on “OK”............................................................... 48
12 PURCHASE............................................................................................................................... 49
13 TECHNICAL QUESTIONS........................................................................................................ 49
www.nordicedge.se Copyright, 2008, Nordic Edge AB Page 3of 49