
Using Security Dynamics Authentication 79
See in the illustration below how the Security Dynamics authentication functions:
The server side
The authentication query by the WAN-Miniport driver uses the following principle:
Example: With the WAN-Miniport driver, a client logs on with the following entries:
User: sales;fred;4893776253
Password: cat
Domain:
In this case the WAN-Miniport driver will filter out ‘fred’ and ‘4893776253’ and forward
them to the ACE/Server for authentication. When the ACE/Server reports that the user is
authorized, the WAN-Miniport driver forwards the user name ‘sales’ and the password
‘cat’ to the RAS.
Windows NT server configuration with Diva Server for Windows NT
The Windows NT server is configured using the Eicon WAN-Miniport driver configuration
on Security Dynamics authentication (see Authentication Features
on page 32).
ACE/Server configuration
Note: Please read the Security Dynamics documentation to configure the ACE/Server.
Please note the following points specifically for setup with the Windows NT server and
Diva Server for Windows NT:
• Communication between the Eicon WAN-Miniport driver and the ACE/Server uses the
TACACS+ protocol. Therefore, set support for authentication via TACACS+ on the
ACE/Server and edit the /etc/services file accordingly.
• Add a client of the ‘Communication Server’ type in ‘sdadmin’.
ACE
Server
Windows NT Server
with
Diva Server for Windows NT
Query over
TAC ACS +
Protocol
Windows 95
Client
SecurID
Tok en
Windows NT
Client
SecurID
oken
ECUR
S
ID
582976
ECUR
S
ID
582976
ISDN
Kommentare zu diesen Handbüchern