Agent Host Configuration
To facilitate communication between the Nortel VPN Gateway and the RSA Authentication Manager / RSA SecurID Appliance, an Agent Host record must be added to the RSA Authentication Manager database. The Agent Host record identifies the Nortel VPN Gateway within its database and contains information about communication and encryption.
To create the Agent Host record, you will need the following information.
•Hostname
•IP Addresses for all network interfaces
•RADIUS Secret (When using RADIUS Authentication Protocol)
When adding the Agent Host Record, you should configure the Nortel VPN Gateway as Communication Server. This setting is used by the RSA Authentication Manager to determine how communication with the Nortel VPN Gateway will occur.
Note: Hostnames within the RSA Authentication Manager / RSA SecurID
Appliance must resolve to valid IP addresses on the local network.
Please refer to the appropriate RSA Security documentation for additional information about Creating, Modifying and Managing Agent Host records.
Additional Steps for RSA Authentication Manager RADIUS Profiles
Configure a RADIUS Profile in the RSA Authentication Manager
The following steps are for administrators configuring the Nortel VPN Gateway 3050 for RSA RADIUS authentication to the RSA Authentication Manager. These steps are not necessary when using with the Native RSA SecurID authentication method.
When configuring RADIUS authentication directly to your RSA Authentication Manager, follow the steps below to configure a RADIUS Profile and assign it to your users. This configuration is basic and only details the minimum steps to get the VPN Gateway 3050 working with the RSA Authentication Manager RADIUS listener. For additional information on RADIUS Profiles, refer to your RSA Authentication Manager Administrative documentation.
1.Within the Profiles menu, select Add Profile.
2.Name your Profile to make it easily identifiable for future usage. e.g. “Nortel VPN Profile”.
3.From the left menu, select
4.Enter a string value as follows : 1872 1 “RADIUS GROUP NAME”
5.Save and Apply your changes.
Note: The string “RADIUS GROUP NAME” refers to the User Group Name configured within the VPN Gateway IOS. This string must match the group to which the RSA SecurID Challenged users belong. This string must be enclosed in double quotes and is case sensitive.
Assign RADIUS Profile to your RSA SecurID Users
1.From the user administration screen, click the button labeled Assign Profile.
2.Select the RADIUS profile you configured in the last section.
3.You will now see the assigned profile listed in the user information screen.
4.Save changes to this user.
4