SAM 8.0 SP2 Deployment at AWS. Version 1.0

Size: px
Start display at page:

Download "SAM 8.0 SP2 Deployment at AWS. Version 1.0"

Transcription

1 SAM 8.0 SP2 Deployment at AWS Version 1.0 Publication Date July 2011

2

3 Copyright 2011 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document complete and accurate. SafeNet, Inc. is not responsible for any direct or indirect damages or loss of business resulting from inaccuracies or omissions. The specifications contained in this document are subject to change without notice. SafeNet, SafeNet Authentication Manager and SafeNet Authentication Client are either registered with the U.S. Patent and Trademark Office or are trademarks of SafeNet, Inc., and its subsidiaries and affiliates, in the United States and other countries. All other trademarks referenced in this Manual are trademarks of their respective owners. SafeNet Hardware and/or Software products described in this document may be protected by one or more U.S. Patents, foreign patents, or pending patent applications. Please contact SafeNet Support for details of FCC Compliance, CE Compliance, and UL Notification. Date of Publication: May 2011 Last update: August 2011 i

4 SAM 8.0 SP2 Deployment at AWS Contacting SafeNet We work closely with our reseller partners to offer the best worldwide technical support services. Your reseller is the first line of support when you have questions about products and services. However, if you require additional assistance you can contact the SafeNet technical support team help-desk which is available 24 hours a day, seven days a week: Country/Region Telephone USA International For further assistance submit additional questions to the SafeNet technical support team at the following web page: For assistance via to SafeNet technical support send the request to the following address: support@safenet-inc.com ii

5 Table of Contents Overview... 6 Virtual Private Cloud (VPC)Components... 7 OTP Scenario Use Case... 8 Main Route Table Recommended Security Groups SRP Security Group SAM Security Group Checklists Step By Step Task 1: Prepare for the VPN Connection...22 Task 2 to Task 6: Create VPC using AWS console...23 Task 7: Create Security Groups and Add Rules Task 8: Launch Instances into the Subnets...34 Task 9: Allocate and Assign Elastic IP Addresses SAM 8.0 SP2 Deployment at AWS (Private Network) SRP Deployment at AWS (Public network) Adding a Portal Connection OTP Plug-in Deployment at Corporate Network Configuring OTP Authentication Settings Step 1- Enroll a MobilePASS Token Step 2- Authenticate Using OTP against a Corporate VPN Server iii

6

7 Chapter 1 Introduction This guide provides basic configuration information required to securely deploy SAM 8.0 SP2 in Amazon Web Services (AWS). This guide introduces the AWS feature Virtual Private Cloud (VPC) which enables communication with a home network over an IPSec VPN tunnel. This guide uses the AWS Management Console to perform Amazon VPC tasks, such as creating virtual private clouds, subnets, and gateways. The console is similar to the Amazon EC2 interface. In addition, Amazon EC2 and Amazon VPC functionality are offered on different tabs in the same AWS Management console. In this chapter: Overview Virtual Private Cloud (VPC)Components OTP Scenario Use Case 5

8 SAM 8.0 SP2 Deployment at AWS Overview Amazon Virtual Private Cloud (Amazon VPC) enables provisioning a private, isolated Amazon Web Services (AWS) Cloud section to launch AWS resources in a defined virtual network. With Amazon VPC, a virtual network topology can be defined to closely resemble a traditional network that is operational in the existing datacenter. There is complete control over a virtual networking environment, including IP address range selection, subnet creation, or route tables and network gateways configuration. The network configuration is easily customized for an Amazon VPC. For example, a public-facing subnet for SafeNet Secure Remote Portal (SRP) 8.0 SP2 servers can be created with access to the Internet, and backend systems such as SafeNet Authentication Manager (SAM) 8.0 SP2 in a private-facing subnet that can be placed with no Internet access. To help control access to Amazon EC2 instances in each subnet, multiple layers of security can be leveraged, including security groups and network access control lists. Additionally, a Hardware Virtual Private Network (VPN) connection can be created between a corporate datacenter and a VPC with the AWS cloud leveraged as a corporate datacenter extension. 6

9 Virtual Private Cloud (VPC)Components VPC is comprised of a variety of objects that is familiar to users with existing networks: A Virtual Private Cloud (VPC) An isolated portion of the AWS cloud. A VPC s IP address space is defined from a range selected by the user. Subnet A VPC IP address range segment where groups of isolated resources can be placed. Internet Gateway The Amazon VPC side of a connection to the public Internet. Hardware VPN Connection A hardware-based VPN connection between an Amazon VPC and the datacenter, home network, or co-location facility. VPN Gateway The Amazon VPC side of a VPN Connection. Customer Gateway The user s side of a VPN Connection. Router Routers interconnect Subnets and direct traffic between Internet gateways, VPN gateways and Subnets. 7

10 SAM 8.0 SP2 Deployment at AWS OTP Scenario Use Case Sometimes an organization requires extending its authentication scheme to use OTP in a typical VPN scenario, for a remote user attempting to access resources on a corporate network. To provide this functionality, the user is required first to enroll an OTP profile that can be either a physical token device or a MobilePASS. MobilePASS token is an application installed on a user s mobile device that generates an OTP passcode. The OTP profile enrollment is performed using the Secure Remote Portal (SRP 8.0 SP2) located in AWS. Note: Other OTP authenticators can be used, for more information, refer to the OTP_Authentication_Admin_Guide_8_0.pdf. After successfully enrolling an OTP profile, a connection through the Internet to the corporate network can be established, and then authenticated to gain access to the corporate resources. The following diagram illustrates a basic VPN scenario and contains the following components. Customer VPN Gateway CheckpointVPN-1 gateway NGX R71 HFA30 Customer Router Cisco ISR IOS 12.4 SAM 8.0 SP2 SRP-8.0 SP2 SafeNet OTP Plug-in 8.0 8

11 Internet 2 VPN-1 gateway NGX R71 HFA30 Safenet OTP Plugin Cisco ISR IOS 12.4 SRP-8.0 SP2 SAM 8.0 SP2 VPC AWS 1 The MobilePASS token enrollment flow is as follows: 1. Client securely connects to SRP 8.0 SP2 server installed at AWS. 2. The client is prompted to enter the MobilePASS Activation Code displayed on the user s mobile device. 3. The user enters an OTP PIN, and confirms the PIN. 4. The MobilePASS token enrollment site on SRP communicates securely with SAM 8.0 SP2 installed on the VPN-only network at AWS, and validates the user credentials A Token Successfully Enrolled message opens. The OTP authentication flow is as follows: 1. A client requests access to a CheckpointVPN-1 gateway. 2. The CheckpointVPN-1 gateway prompts the user for authentication credentials including username, and OTP value. 3. The user opens the MobilePASS application on the mobile device. When the application prompts for the MobilePASS PIN, the user enters the mobile device s Mobile PASS PIN which is set during the MobilePASS Token enrollment. 4. The user generates an OTP which is displayed for a limited period of time. The generated OTP is used, together with the OTP PIN or Windows password if required, to authenticate to the CheckpointVPN-1 gateway. 5. The CheckpointVPN-1 gateway service uses these credentials to authenticate the user via the RADIUS protocol. The authentication request is submitted to the 9

12 SAM 8.0 SP2 Deployment at AWS RADIUS server with Safenet OTP Plugin installed on the customer s network. The Safenet OTP authentication plug-in installed on the RADIUS server validates the request via web services (SOAP over HTTPS) to the SAM 8.0 SP2 validation service installed at AWS. 10

13 Chapter 2 Basic Layout The following diagram illustrates the basic layout of an existing VPC. The larger grey cloud is the existing VPC (the isolated portion of the AWS cloud). There is an Internet gateway attached to the VPC enabling the VPC to communicate with the Internet. There is also a VPN gateway enabling the VPC to communicate with a home network over an IPSec VPN tunnel. The Router in the VPC represents the VPC's built-in routing function. The VPC has two subnets. 1 2 The following table provides additional details about the VPC and its layout for this scenario. A size xx.xx.xx.xx/16 VPC (for example, /16), providing 65,536 private IP addresses. An Internet gateway connecting the VPC to the Internet. 11

14 SAM 8.0 SP2 Deployment at AWS A VPN between the VPC and home network. The entire VPN scenario consists of a customer gateway, VPN gateway, VPN attachment (connecting the VPN gateway to the VPC), and a VPN connection. For this scenario, the VPN setup is generally referred to as the client VPN gateway or VPN connection. To enable the VPN connection, the client must have an appliance (for example a router) in the client s home network operating as the anchor on the client s side of the connection. A size xx.xx.xx.xx/24 subnet (for example, /24), providing 256 private IP addresses. The diagram illustrates the subnet containing an SRP web server with a private IP address (for example, ) and an Elastic IP address (for example, ), enabling the instance to be reached from the Internet. The addresses illustrated in the diagram are examples; when implementing the scenario the values will probably be different. Another subnet, also size /24. In the diagram, the subnet contains backend SAM 8.0 SP2 services for the SRP website and also for the RADIUS server installed at the corporate network. The SAM 8.0 SP2 server has a private IP address (for example, ). Unlike the SRP in the public subnet, the SAM 8.0 SP2 server does not need to accept incoming traffic from the Internet (and should not). Set up the VPC enabling the subnet to receive and send traffic only from the home network (in addition to talking with the public subnet only in specific ports). Therefore in the diagram, the subnet is referred to as VPN-only. Note: For the SRP 8.0 sp2 instance in the public subnet to be reachable from the Internet, the instance must have an associated Elastic IP address. The SAM 8.0 SP2 instance in the VPN-only subnet cannot reach the Internet directly; any Internet-bound traffic must first traverse the VPN gateway to the home network, where the traffic is then subject to the firewall and corporate security policies. 12

15 Chapter 3 Routing A VPC has an implied router, as well as a modifiable main route table. Other route tables can be created to use in the VPC. By default, each table has a local route enabling instances in the VPC to talk to each other. The following diagram and table illustrate the route tables and routes required to set up this scenario. 13

16 SAM 8.0 SP2 Deployment at AWS 1 2 The VPC is automatically configured with a main route table. Any subnet not explicitly associated with another route table uses the main route table. For this scenario, the main route table is updated with a route that sends traffic from the VPN-only subnet to the VPN gateway (the flow of traffic is indicated by the dotted line adjacent to the table). The VPNonly subnet is not explicitly associated with any route table, so it implicitly uses the routes in the main route table. The VPC can have other route tables besides the main route table. This scenario illustrates another route sending traffic from the public subnet to the Internet gateway (the flow of traffic is indicated by the dotted line adjacent to the table). 14

17 Main Route Table If the wizard in the AWS Management Console is used to set up the VPC, the wizard automatically updates the main route table with the route between the VPN-only subnet and the VPN gateway, and creates the custom route table, associating the public subnet with the custom route table. Otherwise the main route table and associating the public subnet with the custom route table must be manually updated. 15

18 SAM 8.0 SP2 Deployment at AWS Chapter 4 Security AWS provides two methods for controlling security in a VPC: security groups and network ACLs. Both enable controlling traffic going in and out of the instances, with security groups working at the instance level, and network ACLs working at the subnet level. For many VPC users, security groups are sufficient, although sometimes both security groups and network ACLs, which take advantage of the additional security layer that network ACLs provide, is required. 16

19 Recommended Security Groups In the example scenario, only security groups and not network ACLs are used. A security group is a group of instances sharing a common set of inbound and outbound rules. To use security groups, create a group, add the required group rules, and then launch instances into the group. Rules can be added and removed from the group, with changes automatically applied to the instances in the group. An instance can be launched into more than one group, and an instance's group membership can be changed after launch. The VPC comes with a default security group with initial settings denying all inbound traffic, allowing all outbound traffic, and allowing all traffic between instances in the group. If a security group is not specified an instance is launched, the instance automatically goes into this default group. Change the group's rules from the initial default rules if it is required that the instances receive traffic from outside the group. For this scenario, it is recommended you do not use the default security group and instead create the following security groups: SRP For the Secure Remote Portal 8.0 SP2 web servers in the public subnet. SAM For the SafeNet Authentication Manager 8.0 SP2 servers in the VPNonly subnet. The following figures illustrate each security group as a circle. A simplified lightgray VPC is in the background to help illustrate how the different VPC parts are related. Each figure has a corresponding table listing the inbound and outbound rules for the group and what they do. 17

20 SAM 8.0 SP2 Deployment at AWS SRP Security Group The SRP security group, launched into the Secure Remote Portal 8.0 SP2 web servers, is based on the rules in the following table. The web servers can only receive secured Internet traffic. The instances can also initiate secured Internet traffic the SafeNet Authentication Manager 8.0 SP2 server instances in the private subnet. Inbound Source Protocol Port Range Comments /0 TCP 443 Allow inbound HTTPS access to the SRP web servers from anyone /24 RDP 3389 Allow inbound Remote Desktop Protocol (RDP) traffic from VPN-only network. 18

21 Outbound Destination Protocol Port Range Comments /24 TCP 443 Allow outbound HTTPS access to the SAM 8.0 SP2 servers from public network. SAM Security Group The SAM security group is launched into the SAM 8.0 SP2 servers. Based on the rules in the following table, the SAM 8.0 SP2 servers can receive secured Internet traffic (HTTPS) from public networks and enables RDP traffic for management. SAM 8.0 SP2 servers also receive HTTPS traffic from RADIUS servers with the SafeNet OTP Plug-in located in the home network. The VPN-only network can initiate RDP traffic to the public network for SRP server management. 19

22 SAM 8.0 SP2 Deployment at AWS Inbound Source Protocol Port Range Comments /24 TCP 443 Allow inbound HTTPS access to SAM 8.0 SP2 servers from public network /16 TCP 443 Allow inbound HTTPS access to SAM 8.0 SP2 servers from corporate network (over VPN Gateway) /16 UDP 3389 Allow inbound RDP traffic from home network (over VPN Gateway). Outbound Destination Protocol Port Range Comments /24 TCP 3389 Allow outbound RDP traffic to the SRP server s public network /24 TCP 443 Allow outbound HTTPS access to the SRP server s public network /16 TCP 443 Allow outbound HTTPS access from SAM 8.0 SP2 servers to corporate network (over VPN Gateway). 20

23 Chapter 5 Implementing the VPC Scenario Checklists These checklists outline the steps required to reach a baseline for a VPC setup with SAM 8.0 SP2 and SRP 8.0 SP2 for OTP usage scenario. Checklist Steps: 1. Setup VPC at AWS. 2. Install SAM 8.0 SP2 instance at VPC (Private network). 3. Install SAM 8.0 SP2 instance at VPC (Public network) 4. Configure RADIUS server with SafeNet OTP Plugin (HQ network). 21

24 SAM 8.0 SP2 Deployment at AWS Step By Step This section describes the process for implementing the previously described scenario. Several tasks (Task 2 to Task 6) are automatically handled when using the wizard in the AWS Management Console. The process for implementing the VPC Scenario is as follows: Task 1: Prepare for the VPN Connection. Task 2: Create the VPC and Subnets. Task 3: Create and Attach the Internet Gateway. Task 4: Create a Custom Route Table and add rules. Task 5: Set Up the VPN Connection. Task 6: Add a Route to the Main Route Table. Task 7: Create Security Groups and Add Rules. Task 8: Launch Instances into the Subnets. Task 9: Allocate and Assign Elastic IP Addresses. Task 1: Prepare for the VPN Connection In the scenario set up a VPN connection between the home network and the VPC. The connection requires an appliance onsite (for example, router) to act as the customer gateway. Help is required from a network administrator to: 22

25 Determine the appliance that is assigned as the customer gateway. Provide the Internet-routable IP address for the customer gateway's external interface. The address must be static and cannot be behind a device performing Network Address Translation (NAT). The following devices meeting the aforementioned requirements are known to work with Hardware VPN connections, and have support in the command line tools for automatic generation of configuration files appropriate for the device: Cisco ISR running Cisco IOS 12.4 (or later) software Juniper J-Series Service Router running JunOS 9.5 (or later) software Juniper SSG running ScreenOS 6.1, or 6.2 (or later) software Juniper ISG running ScreenOS 6.1, or 6.2 (or later) software Any other device can be used; however, it MUST be able to: Establish IKE Security Association using Pre-Shared Keys. Establish IPsec Security Associations in Tunnel mode. Utilize the AES 128-bit encryption function. Utilize the SHA-1 hashing function. Utilize Diffie-Hellman Perfect Forward Secrecy in "Group 2" mode. Establish Border Gateway Protocol (BGP) peering. Bind tunnels to logical interfaces (route-based VPN). Utilize IPsec Dead Peer Detection. Perform packet fragmentation prior to encryption. In the demo, Cisco ISR running Cisco IOS 12.4 software is used. Task 2 to Task 6: Create VPC using AWS console To use the wizard to set up the VPC, the Amazon VPC completes tasks 2-6 by using the wizard in the AWS Management Console. This procedure assumes a VPC is not set up, and that the IP address for the customer gateway (see the preceding task) is available. To use the wizard: 1. Open the AWS Management Console. 2. Select the Amazon VPC tab. The Amazon VPC Console Dashboard opens containing the Your Virtual Private Cloud work area. 23

26 SAM 8.0 SP2 Deployment at AWS 3. On the VPC Dashboard, in the Your Virtual Private Cloud work area click Get started creating a VPC. The wizard opens providing four VPC creating options. 4. Select the option VPC with Public and Private Subnets and Hardware VPN Access, and then click Continue. The VPC with Public and Private Subnets and Hardware VPN Access dialog box opens. 24

27 5. Enter your customer gateway's IP address and click Continue. A confirmation page opens. The Confirmation page displays the CIDR blocks used for the VPC and subnets. It also displays the IP address provided for the customer gateway, as well as the VPC instance hardware tenancy. Any of these values can be edited in the Confirmation page. 6. Modify any details, if required, and then click Create VPC. The wizard begins creating the VPC, subnets, Internet gateway, and VPN connection. It also updates the main route table, creates a custom route table, and adds routes. An incremental bar illustrates the process. 25

28 SAM 8.0 SP2 Deployment at AWS On completion, a confirmation dialog box opens with an option to download the configuration for the customer gateway. 7. Click Download Configuration. The Download Configuration dialog box opens. 8. Select the customer gateway's Vendor, Platform and Software version, and then click Yes, Download. The console responds with a text file containing the configuration. 9. Save the file and give it to the network administrator. The VPN will not work until the network administrator configures the customer gateway. The next task is to create the recommended security groups. 26

29 Task 7: Create Security Groups and Add Rules The AWS console automatically creates a default VPC security group with all ports open. It is advisable to manually create new security groups and add rules to the created groups. This section describes how to manually create new security groups. First create both groups and then add the rules to each. For details about the groups and their rules for this scenario, see the Security chapter. To create a security group: 1. Open the AWS Management Console. 2. Select the Amazon VPC tab. The Amazon VPC page opens. 3. Select the Security Groups page. The Security Groups page opens listing the VPC's security groups. 4. Click Create Security Group. The Create Security Group dialog box opens. 5. Enter the name for the security group (for example, SRP), enter a group description, select the VPC's ID from the VPC menu, and click Yes, Create. The security group is created and appears on the Security Groups page. Notice that the group has an ID (for example, sg-622b390e). The Group ID column may require activating by clicking Show/Hide in the page s top right corner. 27

30 SAM 8.0 SP2 Deployment at AWS 6. Repeat the preceding steps for the (SAM) group. The created security groups must now have rules added to them. To add rules to the SRP security group: 1. In the list of security groups, select the check box for the SRP group. The lower pane displays the security group's details. 2. Add rules for inbound HTTPS access to the group from anywhere: a. In the lower pane select Inbound. The Inbound tab opens. b. On the Inbound tab, from the Create a new rule drop-down list select HTTPS. c. Ensure the Source field's value is /0, and then click Add Rule. The rule to allow HTTPS access from anywhere ( /0) is added to the Inbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply Rule Changes (which is done after adding all the inbound rules to the group). 3. Add rule for inbound RDP access to the group from private a VPN-only network: a. In the lower pane select Inbound. The Inbound tab opens. 28

31 b. On the Inbound tab, from the Create a new rule drop-down list select RDP. c. Ensure the Source field's value is /24, and then click Add Rule. d. The rule to allow RDP access from private network ( /24) is added to the Inbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply Rule Changes (which is done after adding all the inbound rules to the group). 4. Click Apply Rule Changes. The new inbound rules on the right side of the screen are no longer highlighted in blue and the asterisk no longer appears on the tab. The changes indicate that the new inbound rules have been applied. 5. Add the outbound rules to limit egress traffic from the instances: a. Select the Outbound tab. The Outbound tab opens. b. Locate the default rule enabling all outbound traffic, and then click Delete. 29

32 SAM 8.0 SP2 Deployment at AWS The rule is marked for deletion, and an asterisk appears on the tab. The deletion does not take effect until clicking Apply Rule Changes, which is done after adding all the new outbound rules to the group. c. On the Outbound tab, from the Create a new rule drop-down list select HTTPS. d. Ensure the Destination field's value is /24, and then click Add Rule. The rule is added to the Outbound tab. 6. Click Apply Rule Changes. The new outbound rules now apply to the security group. 30

33 The VPC now includes a security group for the SRP servers in the public subnet. The group enabled HTTPS access inbound from anywhere. The group also enables inbound RDP access from the private VPN-only network's IP range. The group also enables HTTPS access to the SAM security group. To add rules to the SAM security group: 1. In the list of security groups, select the check box for the SAM group. The lower pane displays the security group's details. 2. Add rule for inbound HTTPS access to the group from VPC public network: a. In the lower pane select Inbound. The Inbound tab opens. b. On the Inbound tab, from the Create a new rule drop-down list select HTTP. c. Ensure the Source field's value is /24, and then click Add Rule. The rule to allow HTTPS access from public network ( /24) is added to the Inbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply Rule Changes (which is done after adding all the inbound rules to the group). 3. Add rules for inbound HTTPS access from the corporate network: a. In the lower pane select Inbound. The Inbound tab opens. b. On the Inbound tab, from the Create a new rule drop-down list select HTTPS. c. Ensure the Source field's value is /16, and then click Add Rule. The rule enables HTTPS access from the corporate network ( /16) is added to the Inbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply Rule Changes (which is done after adding all the inbound rules to the group). 4. Add rules for inbound RDP access from corporate network: a. In the lower pane select Inbound. The Inbound tab opens. b. On the Inbound tab, from the Create a new rule drop-down list select RDP. c. Ensure the Source field's value is /16, and then click Add Rule. The rule to allow RDP access from corporate network ( /16) is added to the Inbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply 31

34 SAM 8.0 SP2 Deployment at AWS Rule Changes (which is done after adding all the inbound rules to the group). 5. Click Apply Rule Changes. The new inbound rules on the right side of the screen are no longer highlighted in blue and the asterisk no longer appears on the tab. The changes indicate that the new inbound rules have been applied. 6. Add the outbound rules to limit egress traffic from the instances: a. In the lower pane select Outbound. The Outbound tab opens. b. On the Outbound tab, locate the default rule that enables all outbound traffic, and then click Delete. 32

35 The rule is marked for deletion, and an asterisk appears on the tab. The deletion will not take effect until clicking Apply Rule Changes, which is done after adding all the new outbound rules to the group. 7. Add rules for outbound HTTPS access to corporate network: a. In the lower pane select Outbound. The Outbound tab opens. b. On the Outbound tab, from the Create a new rule drop-down list select HTTPS. c. Ensure the Destination field's value is /16, and then click Add Rule. The rule to allow HTTPS access to corporate network /16) is added to the Outbound tab. Notice that the rule on the right is highlighted in blue and an asterisk appears on the tab. This indicates that it is still required to click Apply Rule Changes (which is done after adding all the inbound rules). 8. Add rules for outbound HTTPS access to public network: a. In the lower pane select Outbound. The Outbound tab opens. b. On the Outbound tab, from the Create a new rule drop-down list select HTTPS. c. Ensure the Destination field's value is /24, and then click Add Rule. The rule to allow HTTPS access to VPC Public network ( /24) is added to the Outbound tab. 9. Add rules for outbound RDP access to public network: 33

36 SAM 8.0 SP2 Deployment at AWS a. In the lower pane select Outbound. The Outbound tab opens. b. On the Outbound tab, from the Create a new rule drop-down list select RDP. c. Ensure the Destination field's value is /24, and then click Add Rule. The rule to allow RDP access to VPC Public network ( /24) is added to the Outbound tab. 10. Click Apply Rule Changes. The new outbound rules are applied to the security group. The VPC now includes a security group for the SAM 8.0 SP2 servers in the private VPN-only subnet. The group enables HTTPS and RDP access from the corporate network. The group also enables inbound HTTPS access from the public network's IP range. The group also enables RDP access to the SRP security group for server management. The next section launches instances in the subnets. Task 8: Launch Instances into the Subnets After the network administrator configures the customer gateway, instances can be launched into the VPC. If you have not launched instances before, use the following procedure. If you are already familiar with launching Amazon EC2 instances outside a VPC, then you already know most of what you need to know. 34

37 The additional items to know are as follows: The VPC and subnet to launch the instances in, must be specified. The VPC security group the instance to be in, must be specified (for example, SRP, SAM, etc.). To launch an instance: 1. Start the launch wizard. The following screen opens. 2. Select the Amazon EC2 tab. The Getting Started window opens. 3. Click Launch Instance. The Request Instances Wizard opens. 35

38 SAM 8.0 SP2 Deployment at AWS The first page of the wizard displays tabs listing different Amazon Machine Images (AMI) types. 4. Select an AMI from one of the tabs. If there is not a particular AMI to launch, select the Microsoft Windows Server 2008 Base AMI on the Quick Start tab. The wizard steps to the Instance Details page. The Instance Details page controls settings such as the number and size of instances to launch, and in which subnet to launch the instance. 36

39 5. Select the Launch Instances Into Your Virtual Private Cloud option, and from the Subnet ID drop-down list select the subnet in which to launch the instance. 6. Keep the other default settings on this page and click Continue. The wizard steps to the next page for instance details. 7. Click Continue. The wizard steps to the next page for instance details. 8. Click Continue. 37

40 SAM 8.0 SP2 Deployment at AWS The wizard steps to the Create Key Pair page. A key pair is a security credential similar to a password, which is used to securely connect to an instance once it is running. If you are new to Amazon EC2 and have not created any key pairs yet, then when the wizard displays the Create Key Pair page, the Create a new Key Pair button is selected by default. 9. Create a key pair: a. On the Create Key Pair page, enter a name for the key pair (for example, SAM_Keypair). This is the name of the private key file associated with the pair (with a.pem extension). b. Click Create & Download your Key Pair. A prompt to save the private key from the key pair to the system opens. c. Save the private key in a safe location on the system. Note the location because it is required to use the key to connect to the instance. The wizard steps to the Configure Firewall page. 38

41 10. On the Configure Firewall page, select the security group to use for the instance (for example, SAM or SRP), and then click Continue. The wizard steps to the Review page. The Review page displays all the settings. 11. Review your settings and launch the instance: a. Click Launch. A confirmation page opens indicating the instance is launching. 39

42 SAM 8.0 SP2 Deployment at AWS b. Click Close. The confirmation page is closed. c. In the navigation pane click Instances to view the instance's status. It takes a short time for an instance to launch. The instance's status is pending while it is launching. After a short period, the instance's status switches to running. To refresh the display click Refresh. Now that you know how to launch an instance to VPC you can launch another instance and assign it to the SRP group. The next task associates Elastic IP addresses with SRP servers in the public subnet. Task 9: Allocate and Assign Elastic IP Addresses There should be at least one instance running in each of the subnets. Now Elastic IP addresses can be allocated and assigned to instances in the public subnet. To allocate and assign an Elastic IP address to an instance: 1. Open the AWS Management Console. 2. Select the Amazon VPC tab. The Amazon VPC opens. 3. Select the Elastic IPs page. The Elastic IP page opens. 4. Click Allocate New Address. The Allocate New Address dialog box opens. 40

43 5. From the EIP used in: drop-down list, select VPC, and then click Yes, Allocate. The new address is allocated and is displayed on the page. 6. Right-click the IP addresses in the list and select Associate. The Associate Address dialog box opens. 7. From the Instance: drop-down list select the instance to associate the address with and then click Yes, Associate. The address is associated with the instance. Notice that the instance ID is displayed next to the IP address in the list. The SRP instance now has an Elastic IP address associated with it, and is now accessible from the Internet. 41

44 SAM 8.0 SP2 Deployment at AWS Chapter 6 Connect to the SAM 8.0 SP2 & SRP SP2 Instances at AWS To connect to a Windows instance, the initial administrator password must first be retrieved, and then used with Remote Desktop. The private key file contents created when the instance was launched is required (for example, 2008r2SAM.pem). To connect to your Windows instance: 1. Retrieve the initial administrator password: a. Navigate to the directory where the private key file was stored when the SAM 8.0 SP2 server instance was launched. b. Open the file in a text editor and copy the entire contents (including the first and last lines, which contain BEGIN RSA PRIVATE KEY and END RSA PRIVATE KEY). c. Navigate to the AWS Management Console and locate the instance on the Instances page. d. Right-click the instance and select Get Windows Password. The Retrieve Default Windows Administrator Password dialog box opens (it might take a few minutes after the instance is launched before the password is available). 42

45 e. Into the Private Key field paste the private key file contents. f. Click Decrypt Password. The console returns the default administrator password for the instance. 2. Connect to the instance using Remote Desktop: a. Start the Remote Desktop application (for example, from the Start menu, point to All Programs >Accessories, and then select Remote Desktop Connection). 3. Enter the instance private IP address (which is recorded earlier) and click Connect. 4. Log in using Administrator as the username and the administrator password received in the previous task as the password. You're now connected to your instance. You can work with it like you would any Windows server. Proceed now with the Windows password retrieval for the SRP server instance located in the public network. 43

46 SAM 8.0 SP2 Deployment at AWS Chapter 7 SafeNet Software Deployment This chapter provides a checklist of the main tasks required to install, configure, and deploy SAM 8.0 SP2 and SRP 8.0 SP2 for MobilePASS token enrollment. The chapter includes: SAM 8.0 SP2 Deployment at AWS (Private network) SRP 8.0 SP2 Deployment at AWS (Public network) OTP Plug-in Deployment at Corporate Network 44

47 SAM 8.0 SP2 Deployment at AWS (Private Network) SafeNet Authentication Manager (SAM) 8.0 SP2 enables complete user authentication life cycle management. SafeNet Authentication Manager links tokens with users, organizational rules, and security applications to enable streamlined handling of users' needs throughout the various stages of their authenticator lifecycle. For a checklist of the main tasks required to install, configure, and deploy SAM 8.0 SP2 for MobilePASS token enrollment in an OTP usage scenario, refer to the SAM Administrator s Guide Version 8.0 SP2.pdf. Basic Configuration Order Action Location Reference 1 Install the SafeNet Authentication Manager server component, selecting the OTP installation option. SAM 8.0 SP2 server installed at AWS VPC private network See Installing the SafeNet Authentication Manager Server on page 74 in SAM Administrator s Guide Version 8.0 SP2.pdf. 2 Configure the SafeNet Authentication Manager server. SAM 8.0 SP2 server installed at AWS VPC private network See SAM Configuration Manager on page 283 in SAM Administrator s Guide Version 8.0 SP2.pdf 45

48 SAM 8.0 SP2 Deployment at AWS Ec2ConfigService Configuartion Amazon EC2 Windows Server AMIs reset their hostname on startup due to the Ec2ConfigService. This behavior may cause SAM DB to be not recognized after system reboot. To disable this feature, select EC2ConfigService Settings from the start menu, and uncheck the first checkbox under Set Computer Name To disable reset hostname: 1. Select Start > Programs > EC2ConfigService Settings. The EC2 Service Properties window opens. 2. On the General tab, deselect Set Computer Name 3. Click OK. 46

49 SRP Deployment at AWS (Public network) The SafeNet s Secure Remote Portals (SRP) 8.0 SP2 are configured using the SafeNet Authentication 8.0 SP2 Manager Portals Configuration. For a checklist of the main tasks required to install, configure, and deploy SAM 8.0 SP2 and SRP 8.0 SP2 for MobilePASS token enrollment, see Configuring SAM Portals on page 698 in the SAM Administrator s Guide Version 8.0 SP2.pdf. Adding a Portal Connection A connection must be added for the required MobilePASS Enrollment portal. To add a portal connection: 4. Select Start > Programs > SafeNet > SafeNet Authentication Manager > Portals Configuration. The SafeNet Authentication Manager - Portals Configuration window opens. 5. Select the Connections tab, and click Add. The Connection Details window opens. 47

50 SAM 8.0 SP2 Deployment at AWS 6. Complete the fields as follows: Field Description Connection Name Enter a name for the connection. SAM Server URL Enter the SAM 8.0 SP2 server URL, according to the following format: Username Enter the username (this is the username used for logging on to SAM 8.0 SP2). Password Enter the password (this is the password used for logging on to SAM 8.0 SP2). Instance Name 1. Click Select. The Select SAM instance window opens. 2. Select the instance name of the SAM user store for which the portal connection is to be added. Note: For the Field SAM Server URL, the internal VPC IP address provided by AWS can be used. 48

51 OTP Plug-in Deployment at Corporate Network SafeNet's OTP Plug-In for Microsoft RADIUS Client works with the Microsoft s IAS/NPS Server to provide strong authenticated remote access through the Microsoft IAS/NPS RADIUS Server. When configured, users who access their network remotely using IAS are prompted for a token-generated OTP Passcode to access the network. For configuring the RADIUS server to receive RADIUS requests from a RADIUS client and OTP Plug-In configuration, refer to the OTP Plug-In for Microsoft RADIUS Client on page 542 in the SAM Administrator s Guide Version 8.0 SP2.pdf for a checklist of the main tasks required to install, configure, and deploy the SafeNet OTP Plugin. Configuring OTP Authentication Settings To change the default OTP authentication behavior, modify the OTP configuration settings file, located on the Microsoft RADIUS (IAS/NPS) server. The configuration settings are added to the <ias_plugin_configuration> section in the otp_plugin_config.xml file. The SafeNet's OTP Plug-In is required to communicate with the SAM 8.0 SP2 OTP web service installed at the AWS VPC private network. To configure OTP authentication settings: 1. In the OTP plug-in installation folder, open the otp_plugin_config.xml file for editing. 2. In the <ias_plugin_configuration> section, edit the parameters as follows: Key Value Description Sample otp_web_servic String Defines the SafeNet e_url Authentication Web ntication/service.asmx Service URL. The web server checks all necessary parameters and then authorizes or rejects the request. 49

52 SAM 8.0 SP2 Deployment at AWS Chapter 8 Test the Authentication Scenario To test the OTP scenario, the user has to first enroll an OTP profile which is used for authentication. In this demo, the MobilePASS client software application is used which is enrolled on the user s mobile device to generate an OTP without the need for a physical token. After a MobilePASS token is enrolled the user can proceed and authenticate against the VPN gateway. Step 1- Enroll a MobilePASS Token If it is required to map an existing domain name to an Amazon EC2 instance, one of the DNS management services are required to be used which are available on the Internet. Within Amazon EC2, DNS requests for the external DNS name of an instance are resolved to the internal IP address of the corresponding instance. When using a proprietary domain name, it is recommended to map the instance's external DNS name using a CNAME, not by using a record pointing at the instance's IP address. To enroll a MobilePASS token: 1. Launch your SRP server at AWS: 1.compute.amazonaws.com/sammobile/. The Logon Page opens. 50

53 2. Enter the Username and Password, and then click Submit. The Activation Code Page opens. 51

54 SAM 8.0 SP2 Deployment at AWS 3. Enter the Activation code for the MobilePASS token enrollment, and click Enroll. The enrollment is performed. On completion the Enrollment Completed Page opens. 52

55 The MobilePASS token is successfully enrolled from SRP server installed at AWS. 53

56 SAM 8.0 SP2 Deployment at AWS Step 2- Authenticate Using OTP against a Corporate VPN Server Ensure the VPN gateway is pointed at the corporate network to your RADIUS server with the SafeNet OTP authentication plug-in installed. In this scenario, the RADIUS server with SafeNet OTP authentication plug-in is installed at the corporate network, and it communicates with SAM 8.0 SP2 which is installed at AWS to verify if the OTP is valid. The User now is successfully authenticated with SAM 8.0SP2 installed at the AWS using his MobilePASS token. 54

Protecting SugarCRM with SafeNet Authentication Manager

Protecting SugarCRM with SafeNet Authentication Manager Protecting SugarCRM with SafeNet Authentication Manager Version 8.2 Integration Guide Copyright 2013 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document

More information

Amazon Virtual Private Cloud. User Guide API Version

Amazon Virtual Private Cloud. User Guide API Version Amazon Virtual Private Cloud User Guide Amazon Web Services Amazon Virtual Private Cloud: User Guide Amazon Web Services Copyright 2012 Amazon Web Services LLC or its affiliates. All rights reserved. The

More information

Virtual Private Cloud. User Guide. Issue 03 Date

Virtual Private Cloud. User Guide. Issue 03 Date Issue 03 Date 2016-10-19 Change History Change History Release Date What's New 2016-10-19 This issue is the third official release. Modified the following content: Help Center URL 2016-07-15 This issue

More information

Amazon Virtual Private Cloud. Getting Started Guide

Amazon Virtual Private Cloud. Getting Started Guide Amazon Virtual Private Cloud Getting Started Guide Amazon Virtual Private Cloud: Getting Started Guide Copyright 2017 Amazon Web Services, Inc. and/or its affiliates. All rights reserved. Amazon's trademarks

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager Version 8.0 Rev A User s Guide Copyright 2010 SafeNet, Inc. All rights reserved. All attempts have been made to make the information in this document complete and accurate.

More information

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with SonicWALL E-Class Secure Remote Access

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with SonicWALL E-Class Secure Remote Access SafeNet Authentication Manager Integration Guide SAM using RADIUS Protocol with SonicWALL E-Class Secure Remote Access Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright

More information

FortiMail AWS Deployment Guide

FortiMail AWS Deployment Guide FortiMail AWS Deployment Guide FORTINET DOCUMENT LIBRARY http://docs.fortinet.com FORTINET VIDEO GUIDE http://video.fortinet.com FORTINET BLOG https://blog.fortinet.com CUSTOMER SERVICE & SUPPORT https://support.fortinet.com

More information

Top 30 AWS VPC Interview Questions and Answers Pdf

Top 30 AWS VPC Interview Questions and Answers Pdf Top 30 AWS VPC Interview Questions and Answers Pdf Top 30 AWS VPC Interview Questions and Answers Pdf AWS Certified Solutions Architect Begins the 30 Top Funding IT Certifications. Surely, AWS Architect

More information

Amazon AppStream 2.0: SOLIDWORKS Deployment Guide

Amazon AppStream 2.0: SOLIDWORKS Deployment Guide 2018 Amazon AppStream 2.0: SOLIDWORKS Deployment Guide Build an Amazon AppStream 2.0 environment to stream SOLIDWORKS to your users June 2018 https://aws.amazon.com/appstream2/ 1 Welcome This guide describes

More information

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA SafeNet Authentication Manager Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

Configuring AWS for Zerto Virtual Replication

Configuring AWS for Zerto Virtual Replication Configuring AWS for Zerto Virtual Replication VERSION 1 MARCH 2018 Table of Contents 1. Prerequisites... 2 1.1. AWS Prerequisites... 2 1.2. Additional AWS Resources... 3 2. AWS Workflow... 3 3. Setting

More information

How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud

How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud How to Deploy the Barracuda NG Firewall in an Amazon Virtual Private Cloud The Barracuda NG Firewall can run as a virtual appliance in the Amazon cloud as a gateway device for Amazon EC2 instances in an

More information

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Check Point Security Gateway

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Check Point Security Gateway SafeNet Authentication Manager Integration Guide SAM using RADIUS Protocol with Check Point Security Gateway Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013

More information

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Citrix NetScaler 10.5

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Citrix NetScaler 10.5 SafeNet Authentication Manager Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

EdgeConnect for Amazon Web Services (AWS)

EdgeConnect for Amazon Web Services (AWS) Silver Peak Systems EdgeConnect for Amazon Web Services (AWS) Dinesh Fernando 2-22-2018 Contents EdgeConnect for Amazon Web Services (AWS) Overview... 1 Deploying EC-V Router Mode... 2 Topology... 2 Assumptions

More information

Deploy the Firepower Management Center Virtual On the AWS Cloud

Deploy the Firepower Management Center Virtual On the AWS Cloud Deploy the Firepower Management Center Virtual On the AWS Cloud Amazon Virtual Private Cloud (Amazon VPC) enables you to launch Amazon Web Services (AWS) resources into a virtual network that you define.

More information

Silver Peak EC-V and Microsoft Azure Deployment Guide

Silver Peak EC-V and Microsoft Azure Deployment Guide Silver Peak EC-V and Microsoft Azure Deployment Guide How to deploy an EC-V in Microsoft Azure 201422-001 Rev. A September 2018 2 Table of Contents Table of Contents 3 Copyright and Trademarks 5 Support

More information

AWS VPC Cloud Environment Setup

AWS VPC Cloud Environment Setup AWS VPC Cloud Environment Setup Table of Contents Introduction 3 Requirements 5 Step 1: VPC Deployment Setup 10 Step 2: Launching a VNS3 Controller 15 Instance VNS3 Configuration Document Links 19 2 Introduction

More information

Virtual Private Network. Network User Guide. Issue 05 Date

Virtual Private Network. Network User Guide. Issue 05 Date Issue 05 Date 2018-03-30 Contents Contents 1 Overview... 1 1.1 Concepts... 1 1.1.1 VPN... 1 1.1.2 IPsec VPN...1 1.2 Application Scenarios...2 1.3 Billing Standards... 3 1.4 VPN Reference Standards and

More information

ForeScout CounterACT. (AWS) Plugin. Configuration Guide. Version 1.3

ForeScout CounterACT. (AWS) Plugin. Configuration Guide. Version 1.3 ForeScout CounterACT Hybrid Cloud Module: Amazon Web Services (AWS) Plugin Version 1.3 Table of Contents Amazon Web Services Plugin Overview... 4 Use Cases... 5 Providing Consolidated Visibility... 5 Dynamic

More information

ForeScout Amazon Web Services (AWS) Plugin

ForeScout Amazon Web Services (AWS) Plugin ForeScout Amazon Web Services (AWS) Plugin Version 1.1.1 and above Table of Contents Amazon Web Services Plugin Overview... 4 Use Cases... 5 Providing Consolidated Visibility... 5 Dynamic Segmentation

More information

How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT

How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT Table of Contents TABLE OF CONTENTS 1 INTRODUCTION 2 AWS Configuration: 2 Forcepoint Configuration 3 APPENDIX 7 Troubleshooting

More information

Integration Guide. SafeNet Authentication Service. SAS using RADIUS Protocol with WatchGuard XTMv. SafeNet Authentication Service: Integration Guide

Integration Guide. SafeNet Authentication Service. SAS using RADIUS Protocol with WatchGuard XTMv. SafeNet Authentication Service: Integration Guide SafeNet Authentication Service Integration Guide 1 Document Information Document Part Number 007-012745-001, Rev. A Release Date October 2014 Trademarks All intellectual property is protected by copyright.

More information

Cisco ASA 5500 LAB Guide

Cisco ASA 5500 LAB Guide INGRAM MICRO Cisco ASA 5500 LAB Guide Ingram Micro 4/1/2009 The following LAB Guide will provide you with the basic steps involved in performing some fundamental configurations on a Cisco ASA 5500 series

More information

SelectSurvey.NET AWS (Amazon Web Service) Integration

SelectSurvey.NET AWS (Amazon Web Service) Integration SelectSurvey.NET AWS (Amazon Web Service) Integration Written for V4.146.000 10/2015 Page 1 of 24 SelectSurvey.NET AWS Integration This document is a guide to deploy SelectSurvey.NET into AWS Amazon Web

More information

VMware Cloud on AWS Getting Started. 18 DEC 2017 VMware Cloud on AWS

VMware Cloud on AWS Getting Started. 18 DEC 2017 VMware Cloud on AWS VMware Cloud on AWS Getting Started 18 DEC 2017 VMware Cloud on AWS You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments about

More information

VMware Cloud on AWS Networking and Security. 5 September 2018 VMware Cloud on AWS

VMware Cloud on AWS Networking and Security. 5 September 2018 VMware Cloud on AWS VMware Cloud on AWS Networking and Security 5 September 2018 VMware Cloud on AWS You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

Amazon Virtual Private Cloud. Network Administrator Guide

Amazon Virtual Private Cloud. Network Administrator Guide Amazon Virtual Private Cloud Network Administrator Guide Amazon Virtual Private Cloud: Network Administrator Guide Table of Contents Welcome... 1 Your Customer Gateway... 2 What Is a Customer Gateway?...

More information

VMware AirWatch Certificate Authentication for Cisco IPSec VPN

VMware AirWatch Certificate Authentication for Cisco IPSec VPN VMware AirWatch Certificate Authentication for Cisco IPSec VPN For VMware AirWatch Have documentation feedback? Submit a Documentation Feedback support ticket using the Support Wizard on support.air-watch.com.

More information

Configuring Cisco VPN Concentrator to Support Avaya 96xx Phones Issue 1.0. Issue th October 2009 ABSTRACT

Configuring Cisco VPN Concentrator to Support Avaya 96xx Phones Issue 1.0. Issue th October 2009 ABSTRACT Avaya CAD-SV Configuring Cisco VPN Concentrator to Support Avaya 96xx Phones Issue 1.0 Issue 1.0 30th October 2009 ABSTRACT These Application Notes describe the steps to configure the Cisco VPN 3000 Concentrator

More information

Proxy Protocol Support for Sophos UTM on AWS. Sophos XG Firewall How to Configure VPN Connections for Azure

Proxy Protocol Support for Sophos UTM on AWS. Sophos XG Firewall How to Configure VPN Connections for Azure Proxy Protocol Support for Sophos UTM on AWS Sophos XG Firewall How to Configure VPN Connections for Azure Document date: April 2017 1 Contents 1 Overview... 3 2 Azure Virtual Network and VPN Gateway...

More information

How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway

How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway How to Configure a Site-To-Site IPsec VPN to the Amazon AWS VPN Gateway If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both

More information

SafeNet Authentication Service

SafeNet Authentication Service SafeNet Authentication Service Push OTP Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have

More information

Virtual Private Cloud. User Guide. Issue 21 Date HUAWEI TECHNOLOGIES CO., LTD.

Virtual Private Cloud. User Guide. Issue 21 Date HUAWEI TECHNOLOGIES CO., LTD. Issue 21 Date 2018-09-30 HUAWEI TECHNOLOGIES CO., LTD. Copyright Huawei Technologies Co., Ltd. 2018. All rights reserved. No part of this document may be reproduced or transmitted in any form or by any

More information

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Microsoft DirectAccess

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Microsoft DirectAccess SafeNet Authentication Manager Integration Guide SAM using RADIUS Protocol with Microsoft DirectAccess Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet,

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager Integration Guide Using RADIUS Protocol for F5 BIG-IP Access Policy Manager All information herein is either public information or is the property of and owned solely by

More information

Virtual Private Cloud. User Guide

Virtual Private Cloud. User Guide Alibaba Cloud provides a default VPC and VSwitch for you in the situation that you do not have any existing VPC and VSwitch to use when creating a cloud product instance. A default VPC and VSwitch will

More information

VNS3 to Windows RRAS Instructions. Windows 2012 R2 RRAS Configuration Guide

VNS3 to Windows RRAS Instructions. Windows 2012 R2 RRAS Configuration Guide VNS3 to Windows RRAS Instructions Windows 2012 R2 RRAS Configuration Guide 2018 Site-to-Site IPsec Tunnel IPsec protocol allows you to securely connect two sites together over the public internet using

More information

How to set up a Virtual Private Cloud (VPC)

How to set up a Virtual Private Cloud (VPC) Date published: 15.06.2018 Estimated reading time: 20 minutes Authors: Editorial Team The bookmarks and navigation in this tutorial are optimized for Adobe Reader. How to set up a Virtual Private Cloud

More information

Integration Guide. SafeNet Authentication Manager. Using SafeNet Authentication Manager with Citrix XenApp 6.5

Integration Guide. SafeNet Authentication Manager. Using SafeNet Authentication Manager with Citrix XenApp 6.5 SafeNet Authentication Manager Integration Guide Using SafeNet Authentication Manager with Citrix XenApp 6.5 Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013

More information

F5 BIG-IQ Centralized Management and Amazon Web Services: Setup. Version 5.4

F5 BIG-IQ Centralized Management and Amazon Web Services: Setup. Version 5.4 F5 BIG-IQ Centralized Management and Amazon Web Services: Setup Version 5.4 Table of Contents Table of Contents Getting Started with BIG-IQ Virtual Edition...5 What is BIG-IQ Virtual Edition?...5 About

More information

How to Configure an IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

Building a Modular and Scalable Virtual Network Architecture with Amazon VPC

Building a Modular and Scalable Virtual Network Architecture with Amazon VPC Building a Modular and Scalable Virtual Network Architecture with Amazon VPC Quick Start Reference Deployment Santiago Cardenas Solutions Architect, AWS Quick Start Reference Team August 2016 (revisions)

More information

How to Configure an IPsec Site-to-Site VPN to a Windows Azure VPN Gateway

How to Configure an IPsec Site-to-Site VPN to a Windows Azure VPN Gateway How to Configure an IPsec Site-to-Site VPN to a Windows Azure VPN Gateway To connect your on-premise Barracuda NG Firewall to the static VPN gateway service in the Windows Azure cloud create a IPsec tunnel

More information

FusionHub. SpeedFusion Virtual Appliance. Installation Guide Version Peplink

FusionHub. SpeedFusion Virtual Appliance. Installation Guide Version Peplink FusionHub SpeedFusion Virtual Appliance Installation Guide Version 1.1.0-5 2015 Peplink FusionHub Installation Guide Table of Contents 1. Purpose... 2 2. FusionHub License Generation... 2 3. FusionHub

More information

Configuring VPN from Proventia M Series Appliance to NetScreen Systems

Configuring VPN from Proventia M Series Appliance to NetScreen Systems Configuring VPN from Proventia M Series Appliance to NetScreen Systems January 13, 2004 Overview This document describes how to configure a VPN tunnel from a Proventia M series appliance to NetScreen 208

More information

vcloud Air - Virtual Private Cloud OnDemand Networking Guide

vcloud Air - Virtual Private Cloud OnDemand Networking Guide vcloud Air - Virtual Private Cloud OnDemand Networking Guide vcloud Air This document supports the version of each product listed and supports all subsequent versions until the document is replaced by

More information

Cloud Security Best Practices

Cloud Security Best Practices Cloud Security Best Practices Cohesive Networks - your applications secured Our family of security and connectivity solutions, VNS3, protects cloud-based applications from exploitation by hackers, criminal

More information

PCoIP Connection Manager for Amazon WorkSpaces

PCoIP Connection Manager for Amazon WorkSpaces PCoIP Connection Manager for Amazon WorkSpaces Version 1.0.7 Administrators' Guide TER1408002-1.0.7 Introduction Amazon WorkSpaces is a fully managed cloud-based desktop service that enables end users

More information

Amazon AWS-Solutions-Architect-Professional Exam

Amazon AWS-Solutions-Architect-Professional Exam Volume: 392 Questions Question: 1 By default, Amazon Cognito maintains the last-written version of the data. You can override this behavior and resolve data conflicts programmatically. In addition, push

More information

Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN. VMware Workspace ONE UEM 1810

Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN. VMware Workspace ONE UEM 1810 Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN VMware Workspace ONE UEM 1810 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

How to Configure an IKEv1 IPsec Site-to-Site VPN to the Static Microsoft Azure VPN Gateway

How to Configure an IKEv1 IPsec Site-to-Site VPN to the Static Microsoft Azure VPN Gateway How to Configure an IKEv1 IPsec Site-to-Site VPN to the Static Microsoft Azure VPN Gateway You can configure your local Barracuda NextGen Firewall F-Series to connect to the static IPsec VPN gateway service

More information

Welcome Guide for MP-1 Token for Microsoft Windows

Welcome Guide for MP-1 Token for Microsoft Windows Welcome Guide for MP-1 Token for Microsoft Windows Protecting Your On-line Identity Authentication Service Delivery Made EASY Copyright 2013 SafeNet, Inc. All rights reserved. All attempts have been made

More information

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP

Overview. AWS networking services including: VPC Extend your network into a virtual private cloud. EIP Elastic IP Networking in AWS 2017 Amazon Web Services, Inc. and its affiliates. All rights served. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon Web Services,

More information

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series VPN Configuration Guide Juniper Networks NetScreen / SSG / ISG Series equinux AG and equinux USA, Inc. 2009 equinux USA, Inc. All rights reserved. Under the copyright laws, this manual may not be copied,

More information

Virtual Tunnel Interface

Virtual Tunnel Interface This chapter describes how to configure a VTI tunnel. About s, on page 1 Guidelines for s, on page 1 Create a VTI Tunnel, on page 2 About s The ASA supports a logical interface called (VTI). As an alternative

More information

NetApp Cloud Volumes Service for AWS

NetApp Cloud Volumes Service for AWS NetApp Cloud Volumes Service for AWS AWS Account Setup Cloud Volumes Team, NetApp, Inc. March 29, 2019 Abstract This document provides instructions to set up the initial AWS environment for using the NetApp

More information

Horizon DaaS Platform 6.1 Service Provider Installation - vcloud

Horizon DaaS Platform 6.1 Service Provider Installation - vcloud Horizon DaaS Platform 6.1 Service Provider Installation - vcloud This guide provides information on how to install and configure the DaaS platform Service Provider appliances using vcloud discovery of

More information

SafeNet Authentication Service

SafeNet Authentication Service SafeNet Authentication Service Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep

More information

Configuring VPN from Proventia M Series Appliance to Symantec 5310 Systems

Configuring VPN from Proventia M Series Appliance to Symantec 5310 Systems Configuring VPN from Proventia M Series Appliance to Symantec 5310 Systems January 13, 2004 Overview Introduction This document describes how to configure a VPN tunnel from a Proventia M series appliance

More information

Configuring VPN from Proventia M Series Appliance to Proventia M Series Appliance

Configuring VPN from Proventia M Series Appliance to Proventia M Series Appliance Configuring VPN from Proventia M Series Appliance to Proventia M Series Appliance January 13, 2004 Overview Introduction This document describes how to configure a VPN tunnel from one Proventia M series

More information

How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT

How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT How to Install Forcepoint NGFW in Amazon AWS TECHNICAL DOCUMENT Table of Contents TABLE OF CONTENTS... 1 TEST NETWORK DIAGRAM... 2 PREPARING YOUR VPC... 3 IP addressing... 3 Virtual Private Cloud (VPC)...

More information

VPN Auto Provisioning

VPN Auto Provisioning VPN Auto Provisioning You can configure various types of IPsec VPN policies, such as site-to-site policies, including GroupVPN, and route-based policies. For specific details on the setting for these kinds

More information

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for SonicWALL Secure Remote Access

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for SonicWALL Secure Remote Access SafeNet Authentication Manager Integration Guide Using SAM as an Identity Provider for SonicWALL Secure Remote Access Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright

More information

Deploy and Secure an Internet Facing Application with the Barracuda Web Application Firewall in Amazon Web Services

Deploy and Secure an Internet Facing Application with the Barracuda Web Application Firewall in Amazon Web Services Deploy and Secure an Internet Facing Application with the in Amazon Web In this lab, you will deploy an unsecure web application into Amazon Web (AWS), and then secure the application using the. To create

More information

SafeNet Authentication Service

SafeNet Authentication Service SafeNet Authentication Service Push OTP Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have

More information

Cisco Nexus 1000V InterCloud

Cisco Nexus 1000V InterCloud Deployment Guide Cisco Nexus 1000V InterCloud Deployment Guide (Draft) June 2013 2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 49 Contents

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep

More information

Creating your Virtual Data Centre

Creating your Virtual Data Centre Creating your Virtual Data Centre VPC Fundamentals and Connectivity Options Paul Burne, Senior Technical Account Manager, Enterprise Support - 28 th June 2017 2016, Amazon Web Services, Inc. or its Affiliates.

More information

Elastic Load Balance. User Guide. Issue 14 Date

Elastic Load Balance. User Guide. Issue 14 Date Issue 14 Date 2018-02-28 Contents Contents 1 Overview... 1 1.1 Basic Concepts... 1 1.1.1 Elastic Load Balance... 1 1.1.2 Public Network Load Balancer...1 1.1.3 Private Network Load Balancer... 2 1.1.4

More information

vcloud Director User's Guide

vcloud Director User's Guide vcloud Director 8.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of

More information

CloudEdge Deployment Guide

CloudEdge Deployment Guide Hillstone Networks, Inc. CloudEdge Deployment Guide Version 5.5R3P1 Copyright 2016Hillstone Networks, Inc.. All rights reserved. Information in this document is subject to change without notice. The software

More information

Pexip Infinity and Amazon Web Services Deployment Guide

Pexip Infinity and Amazon Web Services Deployment Guide Pexip Infinity and Amazon Web Services Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring AWS security groups 4 Deploying a Management Node in AWS 6 Deploying a Conferencing Node

More information

Remote Desktop Gateway on the AWS Cloud

Remote Desktop Gateway on the AWS Cloud Remote Desktop Gateway on the AWS Cloud Quick Start Reference Deployment Santiago Cardenas Solutions Architect, AWS Quick Start Team April 2014 Last update: June 2017 (revisions) This guide is also available

More information

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

Deploy ERSPAN with the ExtraHop Discover Appliance and Brocade 5600 vrouter in AWS

Deploy ERSPAN with the ExtraHop Discover Appliance and Brocade 5600 vrouter in AWS Deploy ERSPAN with the ExtraHop Discover Appliance and Brocade 5600 vrouter in AWS Published: 2018-07-06 This guide explains how to install and con#gure an example environment within Amazon Web Services

More information

Amazon AppStream 2.0: Getting Started Guide

Amazon AppStream 2.0: Getting Started Guide 2018 Amazon AppStream 2.0: Getting Started Guide Build an Amazon AppStream 2.0 environment to stream desktop applications to your users April 2018 https://aws.amazon.com/appstream2/ 1 Welcome This guide

More information

vcloud Director User's Guide

vcloud Director User's Guide vcloud Director 8.20 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of

More information

Welcome Guide for KT Series Token

Welcome Guide for KT Series Token Welcome Guide for KT Series Token Protecting Your On-line Identity Authentication Service Delivery Made EASY Copyright 2012 SafeNet, Inc. All rights reserved. All attempts have been made to make the information

More information

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Citrix GoToMyPC

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Citrix GoToMyPC SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP If you are using the Amazon Virtual Private Cloud, you can transparently extend your local network to the cloud by connecting both networks

More information

VPN Configuration Guide. Cisco ASA 5500 Series

VPN Configuration Guide. Cisco ASA 5500 Series VPN Configuration Guide Cisco ASA 5500 Series 2015 equinux AG and equinux USA, Inc. All rights reserved. Under copyright law, this configuration guide may not be copied, in whole or in part, without the

More information

SafeNet Authentication Service

SafeNet Authentication Service SafeNet Authentication Service Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep

More information

HySecure Quick Start Guide. HySecure 5.0

HySecure Quick Start Guide. HySecure 5.0 HySecure Quick Start Guide HySecure 5.0 Last Updated: 25 May 2017 2012-2017 Propalms Technologies Private Limited. All rights reserved. The information contained in this document represents the current

More information

MyIGW Main. Oregon. MyVPC /16. MySecurityGroup / us-west-2b. Type Port Source SSH /0 HTTP

MyIGW Main. Oregon. MyVPC /16. MySecurityGroup / us-west-2b. Type Port Source SSH /0 HTTP MyIGW Main Oregon MyVPC 10.0.0.0/16 10.0.1.0/24 10.0.1.0 -- us-west-2a MySecurityGroup 10.0.2.0/24 10.0.2.0 -- us-west-2b MyWebServer1 MyDBServer DMZ MyInternetRouteTable 0.0.0.0/0 IGW Type Port Source

More information

VNS3 IPsec Configuration. VNS3 to Cisco ASA ASDM 9.2

VNS3 IPsec Configuration. VNS3 to Cisco ASA ASDM 9.2 VNS3 IPsec Configuration VNS3 to Cisco ASA ASDM 9.2 Site-to-Site IPsec Tunnel IPsec protocol allows you to securely connect two sites together over the public internet using cryptographically secured services.

More information

Amazon Web Services Hands- On VPC

Amazon Web Services Hands- On VPC Amazon Web Services Hands- On VPC Copyright 2011-2015, Amazon Web Services, All Rights Reserved Page 1 Table of Contents Overview... 3 Create a VPC... 3 VPC Object Walkthrough... 6 Your VPCs... 6 Subnets...

More information

Pexip Infinity and Amazon Web Services Deployment Guide

Pexip Infinity and Amazon Web Services Deployment Guide Pexip Infinity and Amazon Web Services Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring AWS security groups 4 Deploying a Management Node in AWS 6 Deploying a Conferencing Node

More information

vcloud Director User's Guide 04 OCT 2018 vcloud Director 9.5

vcloud Director User's Guide 04 OCT 2018 vcloud Director 9.5 vcloud Director User's Guide 04 OCT 2018 vcloud Director 9.5 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments about this

More information

Amazon Elastic Compute Cloud

Amazon Elastic Compute Cloud Amazon Elastic Compute Cloud Getting Started Guide AWS Management Console Table of Contents What s New...1 Introduction...2 Setting Up...3 Setting up an AWS Account...3 Signing up for Amazon EC2...3 Signing

More information

PCoIP Connection Manager for Amazon WorkSpaces

PCoIP Connection Manager for Amazon WorkSpaces PCoIP Connection Manager for Amazon WorkSpaces Version 1.0 Administrators' TER1408002-1.0 Contents Who Should Read This 3 What's New 4 Introduction 5 Before You Begin 5 Additional Documentation 6 Network

More information

Establishing secure connectivity between Oracle Ravello and Oracle Cloud Infrastructure Database Cloud ORACLE WHITE PAPER DECEMBER 2017

Establishing secure connectivity between Oracle Ravello and Oracle Cloud Infrastructure Database Cloud ORACLE WHITE PAPER DECEMBER 2017 Establishing secure connectivity between Oracle Ravello and Oracle Cloud Infrastructure Database Cloud ORACLE WHITE PAPER DECEMBER 2017 Table of Contents APPLICATION ARCHITECTURE OVERVIEW 2 CONNECTING

More information

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Tableau Server

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Tableau Server SafeNet Authentication Manager Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

vcloud Director User's Guide

vcloud Director User's Guide vcloud Director 5.6 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more recent editions of

More information

Google Cloud VPN Interop Guide

Google Cloud VPN Interop Guide Google Cloud VPN Interop Guide Using Cloud VPN With Cisco ASA Courtesy of Cisco Systems, Inc. Unauthorized use not permitted. Cisco is a registered trademark or trademark of Cisco Systems, Inc. and/or

More information

Cisco CSR1000V Overview. Cisco CSR 1000V Use Cases in Amazon AWS

Cisco CSR1000V Overview. Cisco CSR 1000V Use Cases in Amazon AWS Cisco CSR1000V Overview The Cisco Cloud Services Router 1000V (CSR 1000V) sets the standard for enterprise network services and security in the Amazon Web Services (AWS) cloud. The Cisco CSR 1000V is based

More information

AWS Remote Access VPC Bundle

AWS Remote Access VPC Bundle AWS Remote Access VPC Bundle Deployment Guide Last updated: April 11, 2017 Aviatrix Systems, Inc. 411 High Street Palo Alto CA 94301 USA http://www.aviatrix.com Tel: +1 844.262.3100 Page 1 of 12 TABLE

More information

Securely Access Services Over AWS PrivateLink. January 2019

Securely Access Services Over AWS PrivateLink. January 2019 Securely Access Services Over AWS PrivateLink January 2019 Notices This document is provided for informational purposes only. It represents AWS s current product offerings and practices as of the date

More information

Configuring Dynamic VPN v2.0 Junos 10.4 and above

Configuring Dynamic VPN v2.0 Junos 10.4 and above Configuring Dynamic VPN v2.0 Junos 10.4 and above Configuring and deploying Dynamic VPNs (remote access VPNs) using SRX service gateways Juniper Networks, Inc. 1 Introduction Remote access VPNs, sometimes

More information

SafeNet Authentication Manager

SafeNet Authentication Manager SafeNet Authentication Manager Integration Guide All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries who shall have and keep

More information