Technical Integration Guide For Entrust Identityguard 7.2 and Cisco VPN 3000 Series Concentrator/Cisco Secure Acs Radius Server
Technical Integration Guide For Entrust Identityguard 7.2 and Cisco VPN 3000 Series Concentrator/Cisco Secure Acs Radius Server
Technical Integration Guide For Entrust Identityguard 7.2 and Cisco VPN 3000 Series Concentrator/Cisco Secure Acs Radius Server
June 2005
Entrust is a registered trademark of Entrust, Inc. in the United States and certain other countries. Entrust is a
registered trademark of Entrust Limited in Canada. All other company and product names are trademarks or
registered trademarks of their respective owners. The material provided in this document is for information
purposes only. It is not intended to be advice. You should not act or abstain from acting based upon such
information without first consulting a professional. ENTRUST DOES NOT WARRANT THE QUALITY,
ACCURACY OR COMPLETENESS OF THE INFORMATION CONTAINED IN THIS ARTICLE. SUCH
INFORMATION IS PROVIDED "AS IS" WITHOUT ANY REPRESENTATIONS AND/OR WARRANTIES OF
ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, BY USAGE OF TRADE, OR OTHERWISE, AND
ENTRUST SPECIFICALLY DISCLAIMS ANY AND ALL REPRESENTATIONS, AND/OR WARRANTIES OF
MERCHANTABILITY, SATISFACTORY QUALITY, NON-INFRINGEMENT, OR FITNESS FOR A SPECIFIC
PURPOSE.
Introduction................................................................................................................................. 1
Entrust Product Information...................................................................................................... 1
Partner Product Information...................................................................................................... 1
Integration Overview .................................................................................................................. 1
Integration Details ...................................................................................................................... 1
System Components ................................................................................................................ 23
Partner Contact Information .................................................................................................... 23
For steps for installing Entrust IdentityGuard 7.2, see the Entrust IdentityGuard 7.2 Installation and Configuration
Guide.
Integration Overview
A Cisco secure VPN can increase confidence in your online security. This enables customers to move higher value
business applications to the Internet — resulting in cost savings.
Entrust IdentityGuard as second-factor authentication can help increase the security of online identities, significantly
improving an organization’s resistance to identity theft attacks such as phishing. It has been designed to address
the real-world demands of strong authentication, making it easier to use while helping to reduce lower deployment
and management costs
Integration Details
In the steps that follow you will be using the administration interfaces of the Cisco Systems VPN 3000 Series
Concentrator and the Cisco Secure ACS RADIUS server to integrate Entrust IdentityGuard with your primary
authentication method.
Configuration includes:
• Configuring the VPN server
• Configuring the RADIUS server
• Configuring the VPN client
• Configuring the IdentityGuard server
Note: The following steps can be performed before or after you install Entrust IdentityGuard 7.2. In either case,
ensure that you note the port numbers and IP address you use, because you will be using them here and in the
installation procedure documented in the Entrust IdentityGuard 7.2 Installation and Configuration Guide.
6. Clicking Add returns you to the first window. Select the name of the newly created group and click
Authentication Servers.
9. Click Add to save your settings. If the Save Needed icon appears in the top right of your screen, click it to
save your settings.
10. In the Configurations menu, select Tunneling and Security >> IPSec, and click IKE Proposals.
You have now completed the configuration of the Cisco Secure ACS RADIUS server and added a user to the
RADIUS server.
Install the IdentityGuard 7.2 server. (See the Entrust IdentityGuard 7.2 Installation and Configuration Guide.)
Create an IdentityGuard user called IGVPNUser1 – the same user you created in the previous section and added to
the RADIUS server. Assign this user and IdentityGuard card.
During IdentityGuard installation, you will enter the shared secrets, IP addresses and ports you provided when you
configured the VPN server and the RADIUS server.
The following steps show you how to configure the Cisco VPN client to communicate with the Cisco VPN server
using the group setting (vpnRadiusTest) that you created in the section “Configuring the VPN server.”
4. In the Host Name or IP address field, enter the Cisco Concentrator Host IP address and click Next.
2. In the User Authentication dialog box, enter the Username (IGVPNUser1) and Password of the user that
you created in the section ”Configuring the RADIUS server.” (You also created this user in Entrust
IdentityGuard and assigned the user a card.) Click OK.
4. An icon on the Taskbar will indicate that you are connected. Double click the icon. The Client Connection
Status window will display details of your connection.
System Components
Entrust IdentityGuard 7.2 Cisco VPN 3000 Series Concentrator
Cisco Secure ACS
Please check PSIC for the latest supported version information at:
https://www.entrust.com/support/psic/index.cfm