Integration Guide for NetMotion Mobility
Before starting, make sure GreenRADIUS is configured with users imported from your LDAP and can communicate with your NetMotion Mobility Server
Configuring GreenRADIUS for NetMotion Mobility
In the GreenRADIUS web admin interface, add the NetMotion Mobility Server as a RADIUS client.
- Click the Domain tab
- Click the domain name where you want to add the NetMotion Mobility Server as a RADIUS client
- Click the RADIUS Clients tab
- Enter the IP address of the NetMotion Mobility Server. Then enter the same RADIUS secret twice. Then click the Add button.
Configuring the NetMotion Mobility Server
Add GreenRADIUS as a RADIUS Server
- Log in to the NetMotion Mobility Server console
- In the main menu, click on the Configure tab > "Authentication Settings"
- Under the "Authentication" section, click "User Authentication Protocol"
- In the "Global Authentication Setting" section, select "RADIUS - EAP (PEAP and EAP-TLS)". Then click "Apply".
- Under the "RADIUS: Device Authentication" section, click "Servers"
- In the "RADIUS Servers" section, click the "Add..." button
- Enter the following:
- Host Address:
[IP address or hostname of GreenRADIUS]
- Port:
1812
- Shared secret:
[enter the same RADIUS secret as configured in GreenRADIUS]
- Confirm shared secret:
[enter the same RADIUS secret as configured in GreenRADIUS]
- Load balancing zone:
0
- Click OK
- The GreenRADIUS entry should now be listed
- Under the "RADIUS: User Authentication" section, click "Servers"
- Repeat Steps 6 - 8 above
- Under the "EAP-GTC" section, click "Auto-Response Mode"
- Uncheck the checkbox for "Auto-response mode" and click Apply
- In the main menu, click on the Configure tab > "Server Settings"
- Under the "Virtual Address" section, click "Allocation Method IPv4"
- In the main menu, click on the Configure tab > "Client Settings"
- Under the "Logon" section, click "Default Credentials"
- In the "Global Setting" section, set as "Windows user"
- In the main menu, click on the Configure tab > "Authentication Settings"
- Under the "Authentication" section, click "Mode"
- In the "Global Authentication Setting" section, set as "User authentication only". Then click "Apply".
NetMotion Mobility Client Configuration
- When installing the NetMotion Mobility client on a Windows machine, be sure to enter the IP address of the NetMotion Mobility server.
- After installation, restart the Windows machine.
- After restarting, the following screen may appear, because the NetMotion Mobility client is not yet configured. Click "Skip".
- Open the NetMotion Mobility client, and click on the "Configuration" button
- Click the "Server Certificates" tab. Then uncheck the checkbox for "Validate server certificate", and click OK.
- Click the "User Certificates" tab. Then uncheck the checkbox for "Allow user certificates", and click OK.
- Restart the Windows machine
- After restarting, log in with a user that already has a token assigned (or will have a YubiKey auto-provisioned upon the first successful login).
- After logging into Windows, the Mobility client login screen will appear. The user should enter his password followed by an OTP (either from a YubiKey or an Authenticator app).
- If the username, password, and OTP are authenticated successfully by GreenRADIUS, the user will be connected to the NetMotion server, and the network will become active and show a status of "Connected".
Avoiding Entering Passwords Twice (Optional)
If you would like users to avoid entering passwords twice (once at the Windows logon screen and again on the NetMotion Mobility client), GreenRADIUS can be configured to skip password validation and only validate token OTPs.
- In the GreenRADIUS web admin interface, under the "Global Configuration" tab, click the "General" icon.
- Set "Enable Password Authentication Through GreenRADIUS" to "No". Then click the "Save" button.
IMPORTANT: This is a global setting, so this would only be recommended if NetMotion is the only 2FA integration with GreenRADIUS.
- When users see the NetMotion Mobility client login screen, users will only need to enter an OTP from their token to log in.
Updated 2024-05-27
© 2024 Green Rocket Security Inc. All rights reserved.
© 2024 Green Rocket Security Inc. All rights reserved.