ProxySG & Advanced Secure Gateway

 View Only
  • 1.  Manage ProxySG WebUI with Radius user

    Posted Sep 10, 2017 10:06 PM

    Hi Guys,

    I have been trying to let Radius users login to the proxySG management UI but am unable to.

    An Admin Authentication Layer and rule to the Radius server has been added

    An Admin Access Layer and rule specifiying Read/Write access for all Radius users have been added

    Tested Radius login via Configurations > Authentication > Radius > Test Configuration and it is successful.

    However I am unbale to login to webUI https://x.x.x.x:8082 via my radius credentials which was successful tested under the Test configurtaion setting. Is there anything else that I missed out? Cant find any KB on this for proxySG. I am using 6.5.10.4. Appreciate any help on this!

    Thanks :)



  • 2.  RE: Manage ProxySG WebUI with Radius user

    Posted Sep 10, 2017 11:41 PM

    You could have ACL in your management access, can you login thru the same pc with the local admin?

    If thats not it, there could be something that needs to be adjusted in your policy.

     

    Philip



  • 3.  RE: Manage ProxySG WebUI with Radius user

    Posted Sep 12, 2017 04:47 AM

    Hi Philip,

    Yes, am able to login to the same PC with the same user. I dont see anything else that could be added to the Admin Authentication Policy though..... :(

    Thanks



  • 4.  RE: Manage ProxySG WebUI with Radius user

    Posted Sep 12, 2017 05:17 AM

    Hi,

    do you get an error message in the browser or in the event log of the SG?

    Does it seems to be more like a connectivity issue or is it the authentication that is failing?

    Regarding the policy - are there any other Admin Authentication layers in the policy or other rules on top of the Radius rule in your Admin Authentication layer?

    Kind Regards,

    Gunnar



  • 5.  RE: Manage ProxySG WebUI with Radius user

    Posted Sep 15, 2017 02:58 AM

    Hi All,

    Thanks for your help. I found the issue. I need a Sequence Realm as I have both Local and Radius Realms I need to authenticate.

    I had to create a Sequence Realm, add both Local and Radius Realms into it then on Admin Authentication Layer, only authenticate with Sequence Realm.

    On the Admin Access Layer, change all users to be under Sequence Realm and thats it! :)