Forum Discussion

tbenner_148572's avatar
tbenner_148572
Icon for Nimbostratus rankNimbostratus
May 01, 2014

APM Policy Two Factor Authentication external and AD authentication internally

Is there a way to use RSA SecureID and two factor Authentciation when people are coming in from externally, but by parsing the ip network if the network is internal use AD authentication and RSA is not needed. All with the APM Access Policy?

 

3 Replies

  • Yes, of course. Use the IP Subnet Agent to determine and branch out authentication options based upon source IP in the Visual Policy Editor.

     

  • We've done this for our SharePoint environment by creating two Virtual Servers on the LTM. The external clients use a two factor auth policy while internal users just AD. Our internal DNS resolve the sharepoint site for clients to one IP while our external DNS Servers advertise a different IP to external clients.

     

    • tbenner_148572's avatar
      tbenner_148572
      Icon for Nimbostratus rankNimbostratus
      I am going to try the IP Subnet Agent first. I thought about creating two virtual servers, but want one due to security department putting in security access rules everywhere