It is assumed that the Astaro Security Gateway UTM is setup and operational. An existing domain user can authenticate using a Domain AD password and access applications, your users can access through IPSec VPN and/or SSL VPN using Domain accounts. 

Register DualShield RADIUS Server

  1. Log in to the WebAdmin interface of the ASG via https://<YourAstaroUTMsIP>:4444
  2. Select “Definitions & Users -> Authentication Servers”
  3. Select “Servers” Tab

  4. Click “New Authentication Server” button



    1. Choose Backend: Radius
    2. Click on the + sign next to Server and enter
    3. Name: DualShield
    4. Type: Host
    5. Address: Your DualShield Radius Server IP Address
    6. In the Pop-Up, click Save
    7. Enter the Shared secret
    8. Click "Test server settings"




    Enter a test Username and Password

    Now, click “Authenticate example user”


Enable Auto User creation for the RADIUS users

  1. Select “Definitions & Users -> Authentication Servers”
  2. Select “Global Settings” Tab
  3. Enable “Create users automatically”
  4. Click Apply.
  5. Choose “End-User Portal” and “SSL VPN”
  6. Click Apply

Allow RADIUS user to access the End-User Portal

In order to get their SSL VPN client and configuration, users have to initially log in to the End User portal. Make sure that RADIUS authenticated users are allowed to log in.

  1. Select “Management -> User Portal”
  2. Add the “Radius Users” group to the list of allowed users. You can choose this group by clicking on the Folder icon and drag and drop it from the list on the left. 

Allow RADIUS users to use the SSL VPN client

  1. Select Remote Access -> SSL
  2. Add the "Radius Users" group to the list of allowed users. You can choose this group by clicking on the Folder icon and drag and drop it from the list on the left.

Allow RADIUS users to use the HTML5 VPN portal

  1. Select Remote Access -> HTML5 VPN Portal
  2. Add the "Radius Users" group to the list of allowed users. You can choose this group by clicking on the Folder icon and drag and drop it from the list on the left.

  • No labels