Technical Integration Guide For Entrust Identityguard 7.2 and Cisco VPN 3000 Series Concentrator/Cisco Secure Acs Radius Server

Download as pdf or txt
Download as pdf or txt
You are on page 1of 26

Technical Integration Guide for Entrust IdentityGuard 7.

2 and Cisco VPN 3000


Series Concentrator/Cisco Secure ACS RADIUS Server

June 2005
Entrust is a registered trademark of Entrust, Inc. in the United States and certain other countries. Entrust is a
registered trademark of Entrust Limited in Canada. All other company and product names are trademarks or
registered trademarks of their respective owners. The material provided in this document is for information
purposes only. It is not intended to be advice. You should not act or abstain from acting based upon such
information without first consulting a professional. ENTRUST DOES NOT WARRANT THE QUALITY,
ACCURACY OR COMPLETENESS OF THE INFORMATION CONTAINED IN THIS ARTICLE. SUCH
INFORMATION IS PROVIDED "AS IS" WITHOUT ANY REPRESENTATIONS AND/OR WARRANTIES OF
ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, BY USAGE OF TRADE, OR OTHERWISE, AND
ENTRUST SPECIFICALLY DISCLAIMS ANY AND ALL REPRESENTATIONS, AND/OR WARRANTIES OF
MERCHANTABILITY, SATISFACTORY QUALITY, NON-INFRINGEMENT, OR FITNESS FOR A SPECIFIC
PURPOSE.

Copyright © 2005. Entrust. All rights reserved.


Contents

Introduction................................................................................................................................. 1
Entrust Product Information...................................................................................................... 1
Partner Product Information...................................................................................................... 1
Integration Overview .................................................................................................................. 1
Integration Details ...................................................................................................................... 1
System Components ................................................................................................................ 23
Partner Contact Information .................................................................................................... 23

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -i-
Introduction
This technical integration guide provides an overview of how to integrate Entrust IdentityGuard 7.2 with the Cisco
VPN 3000 Series Concentrator/Cisco Secure Access Control Server (ACS). Installing Entrust IdentityGuard 7.2 will
allow you to add the benefits of a second factor of authentication to your primary authentication method.

For steps for installing Entrust IdentityGuard 7.2, see the Entrust IdentityGuard 7.2 Installation and Configuration
Guide.

Entrust Product Information


Entrust IdentityGuard 7.2 provides second factor user authentication that is designed to help organizations counter
identity theft by making it more difficult for attackers to steal user online identities.

Partner Product Information


Partner Name: Cisco Systems
Website: www.cisco.com
Product Name: VPN 3000 Series Concentrator
Product Version: 4.7
Product Name: Cisco VPN Client
Product Version: 3.6
Product Name: Cisco Secure ACS for Windows
Product Version: 3.3

Integration Overview
A Cisco secure VPN can increase confidence in your online security. This enables customers to move higher value
business applications to the Internet — resulting in cost savings.

Entrust IdentityGuard as second-factor authentication can help increase the security of online identities, significantly
improving an organization’s resistance to identity theft attacks such as phishing. It has been designed to address
the real-world demands of strong authentication, making it easier to use while helping to reduce lower deployment
and management costs

Integration Details
In the steps that follow you will be using the administration interfaces of the Cisco Systems VPN 3000 Series
Concentrator and the Cisco Secure ACS RADIUS server to integrate Entrust IdentityGuard with your primary
authentication method.

Configuration includes:
• Configuring the VPN server
• Configuring the RADIUS server
• Configuring the VPN client
• Configuring the IdentityGuard server

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -1-
Before you start
• If you haven’t already done so, install the Windows 2000 Server or Windows 2003 Server with Domain
Controller and Active Directory.
• Install the Cisco Secure ACS, using the instructions provided by Cisco Systems.

Note: The following steps can be performed before or after you install Entrust IdentityGuard 7.2. In either case,
ensure that you note the port numbers and IP address you use, because you will be using them here and in the
installation procedure documented in the Entrust IdentityGuard 7.2 Installation and Configuration Guide.

Configuring the VPN server

1. Log in to the VPN server as administrator.


2. In the Configurations menu, select User Management >> Groups, and click Add Group.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -2-
3. On the Identity tab, enter the Group Name and Password and verify the password. (In this example the
new group is called VPNRadiusTest.)

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -3-
4. On the General tab, scroll down and enter the IP address of the Primary DNS server. Select the IPSec
Tunneling protocol checkbox. Leave all other fields with the default values.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -4-
5. On the IPSec tab, select RADIUS from the Authentication dropdown menu. Leave all other fields with the
default values. Scroll down and click Add to save your settings.

6. Clicking Add returns you to the first window. Select the name of the newly created group and click
Authentication Servers.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -5-
7. To add a new Authentication server, click Add.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -6-
8. To configure the new server:
• From the Server Type drop-down menu, select RADIUS.
• In the Authentication Server field, enter the IP address of the IdentityGuard server.
• In the Server Port field, enter 1812 (the default IdentityGuard port).
• In the Server Secret field, enter the RADIUS server shared secret. This is the VPN secret you use
when you install Entrust IdentityGuard.

9. Click Add to save your settings. If the Save Needed icon appears in the top right of your screen, click it to
save your settings.

10. In the Configurations menu, select Tunneling and Security >> IPSec, and click IKE Proposals.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -7-
11. Under Active Proposals, ensure that CiscoVPNClient-3DES-MD5 is moved to the top of the list. Click
Save in the top right corner of the screen.

You have now configured a new VPN server.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -8-
Configuring the RADIUS server
1. Login to the Cisco Secure ACS.

2. To add an AAA Client:


• On the left-hand side of your screen, click Network Configuration.
• Under AAA Clients, click Add Entry.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. -9-
3. To configure the AAA Client:
• In the AAA Client IP Address field, enter the IP Address of the IdentityGuard server.
• In the Key field, enter a shared secret value (this shared secret will be used when you configure Entrust
IdentityGuard).
• From the Authenticate Using dropdown menu, select RADIUS (Cisco VPN 3000).
• Select the Log Update/Watchdog Packets from this AAA Client checkbox.
.

4. Click Submit and Restart to save your configuration

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 10 -
5. To configure the AAA Server:
• On the left-hand side of your screen, click Network Configuration.
• Under AAA Servers, click the existing server link acsradius.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 11 -
6. Update the existing AAA server settings:
• In the AAA Server IP Address field, enter the IP Address of the ACS RADIUS server
• In the Key field, enter a shared secret value. This shared secret is used when you configure Entrust
IdentityGuard.
• Select the Log Update/Watchdog Packets from this AAA Client checkbox.
• From the AAA Server Type dropdown menu, select RADIUS.
• From the Traffic Type dropdown menu, select inbound/outbound.

7. Click Submit and Restart to save your configuration.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 12 -
8. To add a user to RADIUS, on the left-hand side of your screen, click User Setup. Enter a name
(IGVPNUser1) in the User field and click Add/Edit.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 13 -
9. The User Setup window lets you add additional information about the new user. Under User Setup, select
CiscoSecure Database from the Password Authentication drop-down menu.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 14 -
10. Scroll down in the same window and enter and confirm a password for CiscoSecure PAP.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 15 -
11. Scroll down in the same window. To assign the user to a Group, select Default Group from the dropdown
menu. Leave all other fields with the default values.

12. Click Submit to save the new user.

You have now completed the configuration of the Cisco Secure ACS RADIUS server and added a user to the
RADIUS server.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 16 -
Configuring the IdentityGuard server

Install the IdentityGuard 7.2 server. (See the Entrust IdentityGuard 7.2 Installation and Configuration Guide.)

Create an IdentityGuard user called IGVPNUser1 – the same user you created in the previous section and added to
the RADIUS server. Assign this user and IdentityGuard card.

During IdentityGuard installation, you will enter the shared secrets, IP addresses and ports you provided when you
configured the VPN server and the RADIUS server.

Configuring the VPN client

The following steps show you how to configure the Cisco VPN client to communicate with the Cisco VPN server
using the group setting (vpnRadiusTest) that you created in the section “Configuring the VPN server.”

1. Start the Cisco VPN Client application

2. Select New to create a new Connection Entry.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 17 -
3. In the Name of the new connection entry field, enter a name. In this example the name is IGConnection.
Click Next.

4. In the Host Name or IP address field, enter the Cisco Concentrator Host IP address and click Next.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 18 -
5. In the Group Access Information field, enter the Group Name and password you chose when you
configured the VPN server. In this example, the group name is vpnRadiusTest. Click Next.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 19 -
6. Click Finish to return to the first screen to test the connection.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 20 -
Testing the connection
1. Once you have installed all components you can the application by clicking Connect.

2. In the User Authentication dialog box, enter the Username (IGVPNUser1) and Password of the user that
you created in the section ”Configuring the RADIUS server.” (You also created this user in Entrust
IdentityGuard and assigned the user a card.) Click OK.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 21 -
3. In the User Authentication for IGConnect dialog box, enter the IdentityGuard challenge response and
click OK.

4. An icon on the Taskbar will indicate that you are connected. Double click the icon. The Client Connection
Status window will display details of your connection.

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 22 -
Configuring Entrust Products
For installation and configuration of Entrust IdentityGuard 7.2, see the Entrust IdentityGuard 7.2 Installation and
Configuration Guide.

System Components
Entrust IdentityGuard 7.2 Cisco VPN 3000 Series Concentrator
Cisco Secure ACS

Partner Contact Information


Sales and Support Contact: Peter Davis, Product Manager, IPSec VPN, [email protected], (508) 553-6007

Please check PSIC for the latest supported version information at:
https://www.entrust.com/support/psic/index.cfm

© Copyright 2005 Entrust. http://www.entrust.com


All rights reserved. - 23 -

You might also like