1 / 29

Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances

Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances. Vesa Tiihonen, Director Tectia Corporation. September 27 th 2011. Contents. Tectia MobileID Introduction Mobile Authentication – Use Cases and Benefits Key Differentiators of Tectia MobileID Juniper Technology Alliance

yosef
Download Presentation

Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Tokenless Two-Factor Authentication for Juniper SSL VPN Appliances Vesa Tiihonen, Director Tectia Corporation September 27th 2011

  2. Contents • Tectia MobileID Introduction • Mobile Authentication – Use Cases and Benefits • Key Differentiators of Tectia MobileID • Juniper Technology Alliance • SSL VPN Login Use Cases • Tectia MobileID integration with Juniper SSL VPN • Summary

  3. Best tokenless 2FA solution available • Tectia MobileID : a next-generation tokenless authentication solution • Multi-factor appliance designed specifically for on-demand and out-of-band authentication, • Based on high quality SMS One-Time-Password (OTP) as strong authentication technology, • Supports also other OTP delivery methods, such aspassword lists, email OTP, and any OATH compliant hardware and software tokens. • Fully customizable • Operator Grade SMS Messaging Connections Out-Of-The-Box

  4. SMS authentication use cases When to consider tokenless login • When you have geographically dispersed groups of users • When you have a mobile / remote workforce • When you provide an extranet • When you have ad-hoc login requirements • When you do not want to invest in and manage hardware • When you can’t wait weeks for a new token to be delivered

  5. Benefits of using Tectia MobileID • No seed data to be compromised • No security devices to be stolen or lost • 24/7 service deactivation provided by operators, not only by your company helpdesk • One-Time Password unpredictable and 100% random, unlike with tokens • Ability to detect fraudulent activity, e.g. Man-in-the-Middle (MitM/MitB) attacks • Improved user login experience • Less administration • Fewer helpdesk calls

  6. Benefits of using Tectia MobileID Fraud prevention and password management with SMS OTP • Pro-actively lock end user accounts after N failed login attempts • Notification of locked account via SMS • Permit account re-activation via SMS • GeoIP match on Mobile device location • Permit forgotten password/PIN reset via SMS, eliminating the need for helpdesk services Lock my account

  7. Unique Differentiatorsof Tectia MobileID

  8. Unmatched scalability and reliability • Scales to millions of concurrent users • Operator grade SMS delivery world-wide with SLA-guaranteed throughputtimes • Certified to work with • In live productionsince 2003 • Modular architecture that provides service provider-grade scalability,customization and control of networkconditions and business logic

  9. Unmatched TCO and ROI • Flexible pricing models with ability to pay based on active use • Low TCO solution • Practically ZERO administration;new users activated instantly • Tokenless solution – no logistics overhead No extra or hidden costs!

  10. Tectia MobileID – Fast deployment and activation Add/remove traditional token user vs. MobileID:

  11. Tectia MobileID – Superior end-user experience • No end-user training needed • Usage 100% intuitive • No changes to existing login process • Works on any phone, andanywhere in the world So easy it makes your customers smile – guaranteed!

  12. Tectia MobileID – multi-use authentication platform Tectia MobileID can solve ANY ad-hoc multi-factor authentication problem: • 2-factor authentication for SSL VPN access (RADIUS) • 2-factor authentication for Web Services and portals (SOAP) • Solving Man-in-the-Browser / Man-in-the-Middle threats withOut-Of-Band authentication • Multi-domain (LDAP) support • MS Outlook Web Access • Instant Messaging OTP • Any custom ad-hoc on-demand multi-factor authentication use case • 2-factor SMS OTP for MS Windows logins • Supports ALL OTP techniques: email, lists, OATH tokens, Voice, etc. • Cloud-based SMS OTP available Out-Of-The-Box • OTP and business logic for online banking transaction verification

  13. Tectia MobileIDmRules framework Custom business logic for Authentication, Authorization and Access (AAA) • New authentication methods can be added and the existing ones extended • Authentication methods can be chained, triggered, scheduled, etc. • Network packets (i.e. RADIUS) can be re-written, routed, scheduled, etc. Sample custom access rule

  14. Juniper Technology Alliance • Juniper SSL VPN with Tectia MobileID:Full turnkey2FA solutionwithoutthe challenges of firstgenerationtwo-factorauthentication! • Protect against unauthorized access to your critical business information • Reduce your IT administrative workload and hard costs, • Easily scale with tokenless, one time use passcodes delivered via SMS, • Be up an running in hours, not weeks or months! +

  15. Direct integration to existing corporate infrastructure Juniper Technology Alliance 958482 Operator grade global 3G network Third party Gatewayor Integrated Tectia Messaging service One-time password Hello Jane, Your SMS password is 949372 AD/ LDAP Internet Firewall SSL VPN Remote user 15

  16. Authenticating using SMS One-Time Password Scenario 1 – SSL VPN login

  17. Authenticating using SMS One-Time Password On-demand SMS password for two-factor authentication

  18. Authenticating using SMS One-Time Password And you’re logged in!

  19. Authenticating using SMS One-Time Password Scenario 2 – Login with pre-distributed SMS

  20. Authenticating using SMS One-Time Password And you’re logged in!

  21. Technical integration with Juniper SSL VPN Adding a new RADIUS Server to VPN appliance

  22. Technical integration with Juniper SSL VPN Adding a new RADIUS Client to MobileID appliance

  23. Technical integration with Juniper SSL VPN Connecting Tectia MobileID to AD / LDAP

  24. Technical integration with Juniper SSL VPN MobileID is LIVE – Start using it!

  25. Tectia MobileID Web Admin Interface Administer the Virtual Appliance

  26. Viewing Tectia MobileID Logs in Real-Time Viewing Tectia MobileID Logs in Real-Time

  27. Try Tectia MobileID Live Today! • Live VPN demonstration for anybody, anywhere, free-of-charge: • Juniper SSL VPN login: • Register here: http://mobileiddemo.ssh.com/pub/index.php?plugin=register&app=juniper • Login and demo here: http://mobileiddemo.ssh.com/pub/index.php?plugin=testing&app=juniper

  28. Summary Tectia MobileID Competitive Solutions • Operator grade messaging capabilities • Integrated HA messaging • Allows ad-hoc use • Highly scalable • Framework for customized login methods • Certified for Juniper SSL VPN • Typically no operator messaging support • No High Availability (HA), requires purchasing and configuring 3rd party messaging service or product • Accounts must be registered and provisioned to work • Typically for SME use only • Typically only few pre-defined methods available

  29. Thank You! Your People. Your Secrets. Protected.

More Related