Enabling Two-Factor Authentication

Make sure that you get the required RADIUS server details for two-factor authentication from your IT administrator.

Procedure


Step 1

[New Web Interface Only] On the Security Management appliance, click to load the legacy web interface.

Step 2

Choose System Administration > Users page and click Enable under Two-Factor Authentication.

Step 3

Enter the hostname or IP address of the RADIUS server.

Step 4

Enter the port number of the RADIUS server.

Step 5

Enter the Shared Secret passphrase of the RADIUS server.

Step 6

Enter the number of seconds to wait for a response from the server before timing out.

Step 7

Select the appropriate authentication protocol.

Step 8

(Optional) Click Add Row to add another RADIUS server. Repeat steps 2 to 6 for each RADIUS server.

Note
You can add up to ten RADIUS servers.

Step 9

Select the required user roles for which you want to enable two-factor authentication.

Step 10

Submit and commit your changes.

When two-factor authentication is enabled, the user is prompted to enter a passcode after entering the username and passphrase, to login to the appliance.
Note

Users assigned to a role for which two-factor authentication is enabled cannot authenticate to the appliance REST API using HTTP Basic authentication. These users also cannot access the appliance through FTP because HTTP Basic authentication and FTP cannot complete the configured second-factor authentication process.