User Guide

OmniAccess 3500 Nonstop Laptop Guardian Gateway Installation Guide
o User Authentication Type: Method used for authentication of the end users.
Possible values are <DOMAIN>, <RADIUS-LAX>, and <RADIUS-STRICT>. If
<DOMAIN> is selected, the end users will be authenticated using KDC. With the
other two values, a RADIUS server will authenticate the end users. More
specifically, if <RADIUS-LAX> is selected the end-user laptop obtains the usual
network parameters (VPN address and mask, next-hop router, DNS and WINS
servers) before the end user submits the authentication credentials. If
<RADIUS-STRICT> is selected, the network parameters will only be given after
the RADIUS authentication succeeds.
RADIUS Authentication Settings
o Radius IP Address: IP address of the RADIUS server used for authentication of
the end users (relevant only if the User Authentication Type field is set to one
of the RADIUS methods).
o Radius Port: RADIUS server port where the authentication requests must be
addresses.
o Radius Secret: Authentication and encryption key to be used in all RADIUS
communications between the gateway and the RADIUS server.
Kerberos Configuration
o Kerberos Realm: KDC domain of the OmniAccess 3500 NLG gateway. The KDC
domain name is the same as the enterprise domain name, but must be written
in uppercase letters.
o KDC FQDN: Fully Qualified Domain Name (FQDN) of the Active Directory
Server.
o Admin Server: Admin server for the Domain; in most cases it is the same as the
Active Directory Server except when the realm administrator has not made the
information available through DNS.
DNS Settings
o Primary DNS: IP address of the primary DNS name server for end-user traffic.
This entry must be filled with one IP address when the gateway is first
configured. Later on, any modification of the primary DNS name server address
must be applied on the [Gateway Configure-> Server Table Information]
window, reachable through the [Gateway|Configure Advanced Settings|Server
Table] path.
o Secondary DNS: IP address of the secondary DNS name server (optional). This
entry must be filled with one IP address when the gateway is first configured.
Later on, any modification of the secondary DNS name server address must be
applied on the [Gateway Configure-> Server Table Information] window,
reachable through the [Gateway|Configure Advanced Settings|Server Table]
path.
NTP Server Settings
o Primary NTP Server: IP address of the Network Time Protocol (NTP) server
used by the OmniAccess 3500 NLG gateway for time synchronization. Since the
time on the OmniAccess 3500 NLG gateway is critically bound to the time on
34