beautypg.com

HID Fortinet and AAA Server User Manual

Page 10

background image

ActivIdentity 4TRESS AAA Web Tokens and SSL VPN Fortinet Secure Access | Integration Handbook

P 10

External Use | July 16, 2012 | © 2012 ActivIdentity

Bookmarks—Bookmarks are used as links to internal network resources. When a bookmark is
selected from a bookmark list, a pop-up window appears with the web page. Telnet, VNC, and RDP
require a browser plug-in. FTP and Samba replace the bookmarks page with an HTML file-browser.

Connection Tool—Use the Connection Tool widget to connect to an internal network resource
without adding a bookmark to the bookmark list. You select the type of resource and specify the
URL or IP address of the host computer.

Tunnel Mode—If your Web portal provides tunnel mode access, then you have to configure the

Tunnel Mode widget. These settings determine how tunnel mode clients are assigned IP

addresses.

3. Click

Apply.

For more information on how to customize this portal, refer to the document, Fortigate-sslvpn-40-mr3.pdf (full

name: Fortinet SSL VPN ForiOS™ Handbook v3 for FortiOS 4.0 MR3). Locate the document at the following

URL:

http://docs.fortinet.com/fgt/handbook/40mr3/fortigate-sslvpn-40-mr3.pdf



3.3

Procedure 3: Configure the FortiGate Replacement Message

Authentication replacement messages are the prompts a user sees during the security authentication process,

such as a login page, disclaimer page, and login success or failure pages.
Contact your ActivIdentity pre-sales representative to obtain samples of custom pages that integrate the Web soft

token as an option. Then you can upload the sample page into the FortiGate appliance.
However, it’s not possible to upload the Web token applet (.jar file) and the Web token image (.gif) directly into the

FortiGate appliance.
You will have to specify in the “SSL VPN Message” a link to the AAA Self Help Desk portal that hosts these

components. This information is contained in the ActivIdentity sample page. Just copy and paste the sample into

the SSL VPN Login Message, as described next.