Netgear FVS318Gv2 – ProSAFE VPN Firewall Series Reference Manual

Page of 422
 Two-Factor Authentication
409
 NETGEAR ProSAFE VPN Firewall FVS318G v2
The PIN to access your account is 
something you know.
The ATM card is 
something you possess.
You must use both of these factors to gain access to your bank account. Similar to the way 
ATM cards work, access to the corporate networks and data can also be strengthened using 
a combination of multiple factors such as a PIN and a token (hardware or software) to 
validate the users and reduce the incidence of online identity theft.
NETGEAR Two-Factor Authentication Solutions
NETGEAR implements two two-factor authentication solutions from WiKID. WiKID is the 
software-based token solution. So instead of using only Windows Active Directory or LDAP 
as the authentication server, administrators now can use WiKID to perform two-factor 
authentication on NETGEAR VPN firewall products.
The WiKID solution is based on a request-response architecture where a one-time passcode 
(OTP), which is time-synchronized with the authentication server, is generated and sent to 
the user after the validity of a user credential is confirmed by the server.
The request-response architecture is capable of self-service initialization by end users, 
dramatically reducing implementation and maintenance costs. 
Here is an example of how WiKID works:
To use WiKID (for end users):
1. 
Launch the WiKID token software, enter the PIN that was provided (
something the user 
knows), and click the Continue button to receive the OTP from the WiKID 
authentication server: