Configuring the connection to the BlackBerry 2FA server on F5 BIG-IP
BlackBerry 2FA
server on F5
BIG-IP
If you are using
F5
BIG-IP
with an AAA server, you can create an access policy with the Access Policy Manager using the information below.For detailed instructions on how to configure authentication using AAA servers , visit apm_config_server_auth.html to read the
F5
BIG-IP
documentation.When you create the policy, you must set the following options to support
BlackBerry 2FA
:- Set the authentication type to RADIUS
- Specify the IP address or FQDN of the computer that hosts theBlackBerry 2FAserver
- Configure a timeout between 60 and 90 seconds for the connection between the VPN gateway and theBlackBerry 2FAserver
- Set a unique shared secret
- Set the authentication port to 1812
- Verify MS-CHAP v2 is supported
- Turn off Accounting
- Specify the maximum number of login attempts
The policy must be assigned to each
BlackBerry 2FA
server in your environment.