Configuring Administrator Access

On the Device > System > Administrator Access page you can:

  • Configure the IP addresses and interface sources that administrators can use to access the Quantum Spark Appliance.

  • Enable Two-Factor Authentication (2FA) to add an extra layer of security on the gateway.

  • Configure the Web and SSH ports.

Important:

  • Configuring different access permissions for LAN and Internet is not supported when your Internet Connection is configured in bridge mode (the option Allow administration access from does not show Internet or LAN).

  • An automatic implied rule is defined to allow the access specified here. There is no need to add an explicit rule in the Access Policy page to allow this access.

  • When you block the IP address or the interface group through which you are currently connected, you are not disconnected immediately. The access policy is applied immediately, but your current session remains active until you log out.

Two-Factor Authentication (2FA)

Two-Factor Authentication is an extra layer of security on the gateway. When Two-Factor Authentication is enabled on the Administrator Access page, its use is mandatory for all administrators configured on the appliance and is required for login. All administrators must have both an email address and phone number configured.

When Two-Factor Authentication is enabled, if any administrators are missing information, a warning message appears on the DeviceSystem > Administrator Access page that all administrators must first configure an email address and phone number. A list of administrators who are missing information also appears.

Another message that may appear on this page is a recommendation to use a Network Time Protocol (NTP) server to set the date and time on your appliance to avoid sync issues with the Authenticator app.

Note - This feature is available starting from R81.10.10.

Note - In R81.10.10, Two-Factor Authentication is not supported when RADIUS or TACACS is configured for administrator access.

Important - When Two-Factor Authentication is enabled, it is always required for login.

Prerequisites for Two-Factor Authentication

  1. In each administrator object, configure an email address and a phone number. See Configuring Local and Remote System Administrators.

  2. To avoid sync issues with the Authenticator app, use a Network Time Protocol (NTP) sever to set the date and time on your appliance. See Managing Date and Time.