Symantec 14541094 Administration Guide - Page 93

Leveraging centralized authentication in pcAnywhere, Using two-factor authentication

Page 93 highlights

Managing security in Symantec pcAnywhere 93 Controlling access to pcAnywhere hosts 4 Repeat steps 2 and 3 for each computer name or IP address from which you want to allow connections. 5 Click OK. Leveraging centralized authentication in pcAnywhere Symantec pcAnywhere requires you to create a caller logon account for each remote user or user group who connects to the host computer and to select an authentication method for verifying the user's identity. This information is required for all host sessions to prevent unauthorized access. Symantec pcAnywhere supports a number of centralized authentication types, including Active Directory, Novell Directory Services, Novell Bindery, NT, and RSA SecurID, giving you the flexibility of using the authentication measures already in place on your network. Using two-factor authentication Symantec pcAnywhere supports RSA SecurID two-factor authentication. SecurID validates users against a security code which is generated by an authenticator, and a user-provided PIN. You must have the RSA ACE/Server and Agents properly installed and configured on your network. For more information, visit the RSA Web site at the following URL: www.rsa.com To implement SecurID in pcAnywhere, you must do the following: ■ Install and configure the RSA ACE/Agent on the host computer. For more information, see the documentation provided by RSA. ■ On the host computer, open pcAnywhere and configure a host connection item to use SecurID authentication. For more information, see the Symantec pcAnywhere User's Guide. When a remote user attempts to connect to a host computer that uses SecurID authentication, the user is prompted for authentication credentials which include a PIN number, logon name, and passcode. The host computer handles the data requests between the remote computer and the RSA ACE/Agent, which is installed on the host computer. The RSA ACE/Agent handles the data requests between the host computer and the RSA ACE/Server. If the tokencode that is provided by the remote user is out of sync with the server clock or appears to be compromised, the user is prompted for another tokencode.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109

4
Repeat steps
2
and
3
for each computer name or IP address from which you
want to allow connections.
5
Click
OK
.
Leveraging centralized authentication in pcAnywhere
Symantec pcAnywhere requires you to create a caller logon account for each
remote user or user group who connects to the host computer and to select an
authentication method for verifying the user's identity. This information is
required for all host sessions to prevent unauthorized access.
Symantec pcAnywhere supports a number of centralized authentication types,
including Active Directory, Novell Directory Services, Novell Bindery, NT, and
RSA SecurID, giving you the flexibility of using the authentication measures
already in place on your network.
Using two-factor authentication
Symantec pcAnywhere supports RSA SecurID two-factor authentication. SecurID
validates users against a security code which is generated by an authenticator,
and a user-provided PIN.
You must have the RSA ACE/Server and Agents properly installed and configured
on your network.
For more information, visit the RSA Web site at the following URL:
www.rsa.com
To implement SecurID in pcAnywhere, you must do the following:
Install and configure the RSA ACE/Agent on the host computer.
For more information, see the documentation provided by RSA.
On the host computer, open pcAnywhere and configure a host connection item
to use SecurID authentication.
For more information, see the
Symantec pcAnywhere User's Guide
.
When a remote user attempts to connect to a host computer that uses SecurID
authentication, the user is prompted for authentication credentials which include
a PIN number, logon name, and passcode.
The host computer handles the data requests between the remote computer and
the RSA ACE/Agent, which is installed on the host computer. The RSA ACE/Agent
handles the data requests between the host computer and the RSA ACE/Server.
If the tokencode that is provided by the remote user is out of sync with the server
clock or appears to be compromised, the user is prompted for another tokencode.
93
Managing security in Symantec pcAnywhere
Controlling access to pcAnywhere hosts