SLIDE 1
Discuss the challenges with our old VPN system Show what we - - PowerPoint PPT Presentation
Discuss the challenges with our old VPN system Show what we - - PowerPoint PPT Presentation
Discuss the challenges with our old VPN system Show what we replaced it with Demo IT administrators and engineers Faculty accessing research material Staff from Registrar, Admissions Counselors, and Business
SLIDE 2
SLIDE 3
IT administrators and engineers Faculty accessing research material Staff from Registrar, Admissions
Counselors, and Business Divisions
SLIDE 4
How many here have a VPN system? Who has a 2-factor authentication
system integrated with VPN?
SLIDE 5
Is a way of confirming someone’s
identity by challenging them with two separate methods
› Something you know (username/password) › Something you have (token)
SLIDE 6
Windows Point-to-Point (PPTP) VPN Strikeforce ProtectID Out-of-Band
authentication
Connection Process
› User initiates a VPN connection › ProtectID verifies credentials and initiates a
call-back
› User answers their phone and confirms
connection
SLIDE 7
Benefits Limitations
Wide compatibility with devices No need to purchase hardware tokens No having to setup/use software tokens Integration possible for IPSec and SSL VPN
systems
Call back process can be cumbersome Difficult/Impossible to use overseas
SLIDE 8
SLIDE 9
Simplified VPN connection solution Can be used without the need of a
phone call
Can work with PC and smart devices More secure and managed connection
SLIDE 10
New Firewall with VPN
SLIDE 11
Built-in SSL-VPN & IPSec
Support of end users
Supports Windows, OS X,
Linux, iOS 4.0+, Android 4.0.3+
No license limit for # of users* Authentication integrates
easily with Active Directory, LDAP, or RADIUS servers
SLIDE 12
Can use HIP Profiles to
control access
› *Subscription license
required
Limitations:
› No 2-factor
Authentication
SLIDE 13
New 2nd-Factor Authentication system
SLIDE 14
Founded in 2007 Seeking FIPS
certification
Open source server
compnents
Uses 128 bit AES
encryption
Tamper proof casing
SLIDE 15
Provides 2-Factor
authentication
Generates OTP and
types it in for you
Supported by
Windows, OS X, Linux…
Supports Yubico OTP,
OATH-HOTP, Challenge Response, & Static Passwords
SLIDE 16
OTP generator
available for iOS and Android
› If you need to VPN
from a phone or tablet
No support for other
platforms at this time (i.e. Windows Phone, Blackberry, …)
Only works with
- YubiRADIUS. No official
YubiCloud support
SLIDE 17
YubiCloud YubiRAIDUS
Free and easy web API integration Removes complexity of managing a
validation service
Claimed 100% availability since 2010 Free virtual appliance for remote access Integrates with Active Directory or LDAP Uses local key storage module or
hardware security module
Or can use YubiCloud as back-end 2nd-
factor authentication
SLIDE 18
Free virtual appliance in OVF or VMWare
formats
› Small resource footprint
Automatic provisioning of YubiKeys to
users
Redundancy by utilizing two servers and
enabling synchronization
SLIDE 19
SLIDE 20
Easy as 1-2-3
SLIDE 21
Import OVF template Configure network
settings
Secure root and
yubikey account passwords
Configure
Authentication back- end (local or Yubicloud)
Configure global key
provisioning options
SLIDE 22
Add Domain Import desired users
from Active Directory
- r LDAP
Configure domain
level key provisioning
- ptions
Add RADIUS clients
SLIDE 23
Reprogram YubiKeys
with new identities
Upload YubiKey
information to server
Assign Yubikeys to
users
SLIDE 24
Point Firewall/VPN
server to YubiRADIUS server
Use client secret
from earlier
SLIDE 25
Download/Install VPN Client Initiate login Credentials required
›
Username: <Bellarmine username>
›
Password: <Bellarmine password><Yubikey OTP>
Connected
SLIDE 26
“Love this new system…” “…I wholeheartedly think this solution
should completely replace the callback
- solution. “
SLIDE 27