Skip Navigation

Configuring the connection to the 
BlackBerry 2FA
 server on 
F5
 
BIG-IP

If you are using 
F5
 
BIG-IP
 with an AAA server, you can create an access policy with the Access Policy Manager using the information below.
For detailed instructions on how to configure authentication using AAA servers , visit apm_config_server_auth.html to read the 
F5
BIG-IP
 documentation.
When you create the policy, you must set the following options to support 
BlackBerry 2FA
:
  • Set the authentication type to RADIUS
  • Specify the IP address or FQDN of the computer that hosts the 
    BlackBerry 2FA
     server
  • Configure a timeout between 60 and 90 seconds for the connection between the VPN gateway and the 
    BlackBerry 2FA
     server
  • Set a unique shared secret 
  • Set the authentication port to 1812
  • Verify MS-CHAP v2 is supported
  • Turn off Accounting
  • Specify the maximum number of login attempts
The policy must be assigned to each 
BlackBerry 2FA
 server in your environment.