12.1 Configuring Integration with Barracuda SSL VPN

These instructions will help you to configure integration of Advanced Authentication Appliance Edition with the Barracuda SSL VPN virtual appliance to refuse non-secure passwords in Barracuda SSL VPN connection.

The advanced authentication in Barracuda SSL VPN is represented on the following diagram.

To get started, ensure that you have:

  • Barracuda SSL VPN appliance v380 or above (Firmware version 2.6.1.7 was used to prepare these instructions)

  • Advanced Authentication v5 appliance with the already configured repository

Configure the Advanced Authentication RADIUS server:

  1. Open the Advanced Authentication Admin Interface.

  2. Go to the Events section.

  3. Open properties of the Radius Server event.

  4. Set the Radius Server event to the ON mode.

  5. Select one or more chains from the list of Used chains (make sure that they are enabled and set to the users group in the Chains section).

  6. Add a Client, enter an IP address of the Barracuda SSL VPN appliance, specify a secret, confirm it and set the Enabled option.

  7. Click the Save button in the Client string. Click the Save button at the bottom of the Events view to save changes.

Configure the Barracuda SSL VPN appliance:

  1. Sign-in to the Barracuda SSL VPN Configuration portal as ssladmin.

  2. Browse menu Access Control -> Configuration.

  3. Scroll down to RADIUS section.

  4. Enter Advanced Authentication appliance IP address in the RADIUS Server text field.

  5. Specify a shared secret in the Shared Secret text field.

  6. Set Authentication Method to PAP.

  7. Set Reject Challenge to No to allow challenge response.

  8. Click Save Changes.

  9. Switch to Access Control -> User Databases.

  10. Create User Database using the same storage as you are using in the Advanced Authentication.

  11. Switch to Access Control - Authentication Schemes.

  12. In the bottom of the view, click Edit in front of Password scheme for the added User Database.

  13. Move RADIUS from Available modules to Selected modules.

  14. Remove the Password module from the Selected modules.

  15. Apply the changes.

How to authenticate in Barracuda SSL VPN using the Advanced Authentication:

  1. Enter user’s credentials.

  2. Click More and select the configured User Database (if the database is not selected by default).

  3. Click Log In and approve the authentication on the user’s smartphone.

NOTE:Advanced authentication can be configured with other authentication chains.