RSA Security Stonesoft User Manual

RSA SecurID Ready Implementation Guide
Last Modified November 29, 2001
1. Partner Information
Partner Name Stonesoft Corp. Web Site www.stonesoft.com Product Name StoneGate Firewall
Version & Platform Product Description
Product Category Firewall
Version 1.6.3 StoneGate is the first firewall and VPN solution offering high security, high performance and availability. It features: An embedded OS for increased security. Multiple ISP and VPN load balancing to ensure continuous network connectivity. Advanced centralized administration tools for enterprise ­wide management of the firewall infrastructure.
2. Contact Information
E-mail sales@stonesoft.com support@stonesoft.com Phone +358 9 4767 11 +358 9 4767 11 Web www.stonesoft.com www.stonesoft.com
Sales Contact
Support Contact
1
3. Solution Summary
Feature Details
Authentication Methods Supported RADIUS, TACACS+. ACE/Agent Library Version N/A ACE 5 Locking N/A Replica ACE/Server Support N/A Secondary RADIUS/TACACS+
Yes (up to 10 supported)
Server Support Location of Node Secret on Client None stored ACE/Server Agent Host Type UNIX Agent SecurID User Specification Designated users, all users, SecurID as
default.
SecurID Protection of
No
Administrators
StoneGate system architecture.
GUI client
GUI client
Authentication servers
GUI client
Management system
ACE/Server
Primary
&
Replica
Database
Log
server
Node 2Node 1 Node 3
Management
server
Firewall cluster
Database
2
4. Product Requirements
Hardware requirements
Component Name: StoneGate Management system
CPU make/speed required Pentium processor, suggested minimum processor speed
500 MHz Memory 128 MB minimum, 256 MB or more recommended HD space 4GB for evaluation (20 GB or more for production use).
Component Name: StoneGate Firewall Engine
CPU make/speed required Pentium processor, suggested minimum processor speed
300 MHz Memory 128 MB HD space 1 GB
Software requirements
Component Name: StoneGate Management System
Operating System Version (Patch-level)
Windows NT 4.0 Service Pack 6a, English language version Windows 2000 Service Pack 2, English language version Sun Solaris 2.6 & 2.7 RedHat Linux 7.0 and 7.1, English language version
Component Name: StoneGate Firewall engine
Operating System Version (Patch-level)
Linux–based, provided with product
1.6.3
3
5. Partner ACE/Agent configuration
Supported authentication types with RSA SecurID product
Client-initiated authentication
Client initiated authentication means that the user starts the authentication process. It can be done with two tools: Authentication Client software (part of StoneGate VPN Client software) or using Telnet to connect to the firewall cluster on port 2543.
It is possible to authorize the client's IP address for a period of time with client initiated authentication. It is also possible to authorize the next opening connection from the client. The authorization part is specified in the access rule base.
Firewall-initiated authentication
Firewall-initiated authentication means that the firewall cluster starts the authentication process. It can be used only with the Authentication Client software. This software is part of StoneGate VPN Client software.
In firewall initiated authentication the firewall makes the connection to the client. This naturally requires that the client is reachable, e.g. there can't be NAT between firewall engine and the client.
With firewall initiated authentication it is also possible to authorize either the client's IP address or the current connection.
No software, other than StoneGate Management system and StoneGate firewall -engine are required to support Client initiated authentication, though the Authentication Client software included in the StoneGate VPN Client can be used.
For Firewall initiated authentication support the StoneGate Authentication Client software MUST be used.
4
Loading...
+ 7 hidden pages