Working with Authentication

Authentication Schemes

Authentication schemes employ user names and passwords to identify valid users.

Some schemes are maintained locally, storing user names and passwords on the VSX GatewayClosed Physical server that hosts VSX virtual networks, including all Virtual Devices that provide the functionality of physical network devices. It holds at least one Virtual System, which is called VS0., while others store authentication information on an external authentication server.

Some schemes, such as SecurID, are based on providing a one-time password.

For more information, see the R81.10 Security Management Administration Guide > Section Configuring Authentication Methods for Users.

Configuring SecurID Authentication

See the R81.10 Security Management Administration Guide > Chapter Managing User and Administrator Accounts > Section Managing User Accounts > Section SecurID Authentication for Security Gateway.

Configuring RADIUS or TACACS Authentication

These are the options to enable connectivity between Virtual Systems and a RADIUS or TACACS/TACACS+ server:

For Multi-Domain ServerClosed Dedicated Check Point server that runs Check Point software to host virtual Security Management Servers called Domain Management Servers. Synonym: Multi-Domain Security Management Server. Acronym: MDS. configurations, make sure that you configure the SecurID or Remote Authentication settings of the Domain Management Server that manages the Virtual Systems.