Discuss the challenges with our old VPN system Show what we replaced it with Demo
IT administrators and engineers Faculty accessing research material Staff from Registrar, Admissions Counselors, and Business Divisions
How many here have a VPN system? Who has a 2-factor authentication system integrated with VPN?
Is a way of confirming someone’s identity by challenging them with two separate methods › Something you know (username/password) › Something you have (token)
Windows Point-to-Point (PPTP) VPN Strikeforce ProtectID Out-of-Band authentication Connection Process › User initiates a VPN connection › ProtectID verifies credentials and initiates a call-back › User answers their phone and confirms connection
Wide compatibility with devices No need to purchase hardware tokens No having to setup/use software tokens Benefits Integration possible for IPSec and SSL VPN systems Call back process can be cumbersome Difficult/Impossible to use overseas Limitations
Simplified VPN connection solution Can be used without the need of a phone call Can work with PC and smart devices More secure and managed connection
New Firewall with VPN
Built-in SSL-VPN & IPSec Support of end users Supports Windows, OS X, Linux, iOS 4.0+, Android 4.0.3+ No license limit for # of users* Authentication integrates easily with Active Directory, LDAP, or RADIUS servers
Can use HIP Profiles to control access › *Subscription license required Limitations: › No 2-factor Authentication
New 2 nd -Factor Authentication system
Founded in 2007 Seeking FIPS certification Open source server compnents Uses 128 bit AES encryption Tamper proof casing
Provides 2-Factor authentication Generates OTP and types it in for you Supported by Windows, OS X, Linux… Supports Yubico OTP, OATH-HOTP, Challenge Response, & Static Passwords
OTP generator available for iOS and Android › If you need to VPN from a phone or tablet No support for other platforms at this time (i.e. Windows Phone, Blackberry, …) Only works with YubiRADIUS. No official YubiCloud support
Free and easy web API integration Removes complexity of managing a validation service YubiCloud Claimed 100% availability since 2010 Free virtual appliance for remote access Integrates with Active Directory or LDAP YubiRAIDUS Uses local key storage module or hardware security module Or can use YubiCloud as back-end 2nd- factor authentication
Free virtual appliance in OVF or VMWare formats › Small resource footprint Automatic provisioning of YubiKeys to users Redundancy by utilizing two servers and enabling synchronization
Easy as 1-2-3
Import OVF template Configure network settings Secure root and yubikey account passwords Configure Authentication back- end (local or Yubicloud) Configure global key provisioning options
Add Domain Import desired users from Active Directory or LDAP Configure domain level key provisioning options Add RADIUS clients
Reprogram YubiKeys with new identities Upload YubiKey information to server Assign Yubikeys to users
Point Firewall/VPN server to YubiRADIUS server Use client secret from earlier
Download/Install VPN Client Initiate login Credentials required Username: <Bellarmine username> › Password: <Bellarmine password><Yubikey OTP> › Connected
“Love this new system…” “…I wholeheartedly think this solution should completely replace the callback solution. “
Tony Morrow amorrow@bellarmine.edu Bellarmine University
Recommend
More recommend