5.1

Table Of Contents
14 In the Advanced section, type the IP address of the vShield Edge interface through which the RSA server
is accessible.
15 Select Use this server for secondary authentication if you want to use this server as the second level of
authentication.
Select Terminate Session if authentication fails if required.
16 Click OK.
Add Local Authentication Server
You can add a local authentication server to bound to the SSL gateway. All users in the bounded authenticated
server will be authenticated.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge instance.
6 Click the VPN tab.
7 Click the SSL VPN-Plus tab.
8 In the Configure panel, click Authentication.
9
Click the Add ( ) icon
The Add Server dialog box opens.
10 In Type, select LOCAL.
11 To define a password policy, select Password Policy and specify the required values.
12 To define an account lockout policy, select Enable next to Account Lockout Policy.
a In Retry Count, type the number of times a remote user can try to access his or her account after
entering an incorrect password.
b In Retry Duration, type the time period in which the remote user's account gets locked on
unsuccessful login attempts.
For example, if you specify Retry Count as 5 and Retry Duration as 1 minute, the remote user's
account will be locked if he makes 5 unsuccessful login attempts within 1 minute.
c In Lockout Duration, type the time period for which the user account remains locked. After this time,
the account is automatically unlocked.
13 Select Enabled or Disabled to indicate whether the server is enabled.
14 Select Use this server for secondary authentication if you want to use this server as the second level of
authentication.
Select Terminate Session if authentication fails if required.
15 Click OK.
Chapter 9 vShield Edge Management
VMware, Inc. 111