ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)

ื“ื™ ื ื•ื™ื˜ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ืฆื• ืึท ืคึฟื™ืจืžืข ืกื•ื•ื™ื•ื•ืข ืื™ื– ื™ืžืขืจื“ื–ืฉื™ื ื’ ืžืขืจ ืื•ืŸ ืžืขืจ ืึธืคื˜, ืงื™ื™ืŸ ืขื ื™ืŸ ืฆื™ ืขืก ื–ืขื ืขืŸ ื“ื™ื™ืŸ ื™ื•ื–ืขืจื– ืึธื“ืขืจ ืคึผืึทืจื˜ื ืขืจืก ื•ื•ืึธืก ื“ืึทืจืคึฟืŸ ืึทืงืกืขืก ืฆื• ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืกืขืจื•ื•ืขืจ ืื™ืŸ ื“ื™ื™ืŸ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข.

ืคึฟืึทืจ ื“ื™ ืฆื•ื•ืขืงืŸ, ืจื•ื‘ึฟ ืงืึธืžืคึผืึทื ื™ืขืก ื ื•ืฆืŸ VPN ื˜ืขื›ื ืึธืœืึธื’ื™ืข, ื•ื•ืึธืก ื”ืื˜ ืคึผืจืึธื•ื•ืขืŸ ื–ื™ืš ืฆื• ื–ื™ื™ืŸ ืึท ืจื™ืœื™ื™ืึทื‘ืœื™ ืคึผืจืึธื˜ืขืงื˜ืขื“ ื•ื•ืขื’ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึทืงืกืขืก ืฆื• ื“ื™ ื”ื™ื’ืข ืจืขืกื•ืจืกืŸ ืคื•ืŸ ื“ืขืจ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข.

ืžื™ื™ึทืŸ ืคื™ืจืžืข ืื™ื– ื’ืขื•ื•ืขืŸ ืงื™ื™ืŸ ื•ื™ืกื ืขื, ืื•ืŸ ืžื™ืจ, ื•ื•ื™ ืคื™ืœืข ืื ื“ืขืจืข, ื ื•ืฆืŸ ื“ืขื ื˜ืขื›ื ืึธืœืึธื’ื™ืข. ืื•ืŸ, ื•ื•ื™ ืคื™ืœืข ืื ื“ืขืจืข, ืžื™ืจ ื ื•ืฆืŸ Cisco ASA 55xx ื•ื•ื™ ืึท ื•ื•ื™ื™ึทื˜ ืึทืงืกืขืก ื’ื™ื™ื˜ื•ื•ื™ื™.

ื•ื•ื™ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ื ื™ืฆืขืจืก ื™ื ืงืจื™ืกื™ื–, ืขืก ืื™ื– ืึท ื ื•ื™ื˜ ืฆื• ืคืึทืจืคึผืึธืฉืขื˜ืขืจืŸ ื“ื™ ืคึผืจืึธืฆืขื“ื•ืจ ืคึฟืึทืจ ืืจื•ื™ืกื’ืขื‘ืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ืื‘ืขืจ ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ึทื˜, ื“ืึธืก ืžื•ื–ืŸ ื–ื™ื™ืŸ ื’ืขื˜ืืŸ ืึธืŸ ืงืึทืžืคึผืจืึทืžื™ื™ื–ื™ื ื’ ื–ื™ื›ืขืจืงื™ื™ึทื˜.

ืคึฟืึทืจ ื–ื™ืš, ืžื™ืจ ื’ืขืคึฟื•ื ืขืŸ ืึท ืœื™ื™ื–ื•ื ื’ ืื™ืŸ ื ื™ืฆืŸ ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื•ืจืš Cisco SSL VPN, ื ื™ืฆืŸ ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืคึผืึทืกื•ื•ืขืจื“ื–. ืื•ืŸ ื“ื™ ื•ื™ืกื’ืึทื‘ืข ื•ื•ืขื˜ ื–ืึธื’ืŸ ืื™ืจ ื•ื•ื™ ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ืึทื–ืึท ืึท ืœื™ื™ื–ื•ื ื’ ืžื™ื˜ ืžื™ื ื™ืžืึทืœ ืฆื™ื™ื˜ ืื•ืŸ ื ื•ืœ ืงืึธืก ืคึฟืึทืจ ื“ื™ ื ื™ื™ื˜ื™ืง ื•ื•ื™ื™ื›ื•ื•ืืจื’ (ืฆื•ื’ืขืฉื˜ืขืœื˜ ืึทื– ืื™ืจ ืฉื•ื™ืŸ ื”ืึธื‘ืŸ Cisco ASA ืื™ืŸ ื“ื™ื™ืŸ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ).

ื“ืขืจ ืžืึทืจืง ืื™ื– ืจื™ืคึผืœื™ื˜ ืžื™ื˜ ื‘ืึธืงืกืขื“ ืกืึทืœื•ืฉืึทื ื– ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืคึผืึทืกื•ื•ืขืจื“ื–, ืื•ืŸ ืึธืคืคืขืจืก ืึท ืคึผืœืึทืฅ ืคื•ืŸ ืึธืคึผืฆื™ืขืก ืฆื• ื‘ืึทืงื•ืžืขืŸ ื–ื™ื™, ื–ื™ื™ืŸ ืขืก ืฉื™ืงื˜ ื“ื™ ืคึผืึทืจืึธืœ ื“ื•ืจืš SMS ืึธื“ืขืจ ื ื™ืฆืŸ ื˜ืึธืงืขื ืก, ื‘ื™ื™ื“ืข ื™ื™ึทื–ื ื•ื•ืึทืจื’ ืื•ืŸ ื•ื•ื™ื™ื›ื•ื•ืืจื’ (ืœืžืฉืœ, ืื•ื™ืฃ ืึท ืจื™ืจืขื•ื•ื“ื™ืง ื˜ืขืœืขืคืึธืŸ). ืึธื‘ืขืจ ื“ืขืจ ืคืึทืจืœืึทื ื’ ืฆื• ืฉืคึผืึธืจืŸ ื’ืขืœื˜ ืื•ืŸ ื“ืขืจ ืคืึทืจืœืึทื ื’ ืฆื• ืฉืคึผืึธืจืŸ ื’ืขืœื˜ ืคึฟืึทืจ ืžื™ื™ืŸ ื‘ืึทืœืขื‘ืึธืก, ืื™ืŸ ื“ืขื ืงืจืึทื ื˜ ืงืจื™ื–ื™ืก, ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืžื™ืจ ืฆื• ื’ืขืคึฟื™ื ืขืŸ ืึท ืคืจื™ื™ ื•ื•ืขื’ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ืึท ื“ื™ื ืกื˜ ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืคึผืึทืกื•ื•ืขืจื“ื–. ื•ื•ืึธืก, ื›ืึธื˜ืฉ ืคืจื™ื™, ืื™ื– ื ื™ืฉื˜ ืคื™ืœ ืขืจื’ืขืจ ืฆื• ื’ืขืฉืขืคื˜ ืกืึทืœื•ืฉืึทื ื– (ื“ืึธ ืžื™ืจ ื–ืึธืœ ืžืึทื›ืŸ ืึท ืจืขื–ืขืจื•ื•ืึทืฆื™ืข, ื‘ืืžืขืจืงื˜ ืึทื– ื“ืขื ืคึผืจืึธื“ื•ืงื˜ ืื•ื™ืš ื”ืื˜ ืึท ื’ืขืฉืขืคื˜ ื•ื•ืขืจืกื™ืข, ืึธื‘ืขืจ ืžื™ืจ ืžืกื›ื™ื ืึทื– ืื•ื ื“ื–ืขืจ ืงืึธืก ืื™ืŸ ื’ืขืœื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื ื•ืœ).

ืึทื–ื•ื™, ืžื™ืจ ื•ื•ืขืœืŸ ื“ืึทืจืคึฟืŸ:

- ื ืœื™ื ื•ืงืก ื‘ื™ืœื“ ืžื™ื˜ ืึท ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ื’ืึทื ื’ ืคื•ืŸ ืžื›ืฉื™ืจื™ื - ืžื•ืœื˜ื™ืึธื˜ืคึผ, ืคืจืขืขืจืึทื“ื™ื•ืก ืื•ืŸ ื ื’ื™ื ืงืก, ืคึฟืึทืจ ืึทืงืกืขืก ื“ื™ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ื“ื™ ื•ื•ืขื‘ (http://download.multiotp.net/ - ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ ืึท ืคืึทืจื˜ื™ืง ื‘ื™ืœื“ ืคึฟืึทืจ VMware)
- ืึทืงื˜ื™ื•ื• Directory ืกืขืจื•ื•ื™ืจืขืจ
- Cisco ASA ื–ื™ืš (ืคึฟืึทืจ ืงืึทื ื•ื•ื™ื ื™ืึทื ืก, ืื™ืš ื ื•ืฆืŸ ASDM)
- ืงื™ื™ืŸ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืกื™ืžืขืŸ ื•ื•ืึธืก ืฉื˜ื™ืฆื˜ ื“ื™ TOTP ืžืขืงืึทื ื™ื–ืึทื (ืื™ืš, ืœืžืฉืœ, ื ื•ืฆืŸ Google Authenticator, ืึธื‘ืขืจ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ FreeOTP ื•ื•ืขื˜ ื˜ืึธืŸ)

ืื™ืš ื•ื•ืขืœ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืื™ืŸ ืคืจื˜ื™ื ืคื•ืŸ ื•ื•ื™ ื“ื™ ื‘ื™ืœื“ ืึทื ืคืึธื•ืœื“ื–. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืื™ืจ ื•ื•ืขื˜ ื‘ืึทืงื•ืžืขืŸ ื“ืขื‘ื™ืึทืŸ ืœื™ื ื•ืงืก ืžื™ื˜ MultiOTP ืื•ืŸ FreeRADIUS ืฉื•ื™ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืงืึทื ืคื™ื’ื™ืขืจื“ ืฆื• ืึทืจื‘ืขื˜ืŸ ืฆื•ื–ืึทืžืขืŸ ืื•ืŸ ืึท ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืคึฟืึทืจ ืึธื˜ืคึผ ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข.

ืฉืจื™ื˜ 1. ืžื™ืจ ืึธื ื”ื™ื™ื‘ืŸ ื“ื™ ืกื™ืกื˜ืขื ืื•ืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืขืก ืคึฟืึทืจ ื“ื™ื™ืŸ ื ืขืฅ
ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ืกื™ืกื˜ืขื ืงื•ืžื˜ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ื•ื•ืึธืจืฆืœ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ืื™ืš ื˜ืจืึทื›ื˜ืŸ ืึทืœืขืžืขืŸ ื’ืขืกื˜ ืึทื– ืขืก ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืึท ื’ื•ื˜ืข ื’ืขื“ืึทื ืง ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ ืคึผืึทืจืึธืœ ื ืึธืš ื“ืขืจ ืขืจืฉื˜ืขืจ ืœืึธื’ื™ืŸ. ืื™ืจ ืื•ื™ืš ื“ืึทืจืคึฟืŸ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ื ืขืฅ ืกืขื˜ื˜ื™ื ื’ืก (ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืขืก ืื™ื– '192.168.1.44' ืžื™ื˜ ื“ื™ ื’ื™ื™ื˜ื•ื•ื™ื™ '192.168.1.1'). ื“ืขืจื ืึธืš ืื™ืจ ืงืขื ืขืŸ ืจื™ืกื˜ืึทืจื˜ ื“ื™ ืกื™ืกื˜ืขื.

ืœืึธืžื™ืจ ืฉืึทืคึฟืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ืื™ืŸ ืึทืงื˜ื™ื•ื• Directory ืึธื˜ืคึผ, ืžื™ื˜ ืคึผืึทืจืึธืœ MySuperPassword.

ืฉืจื™ื˜ 2. ืฉื˜ืขืœืŸ ืึทืจื•ื™ืฃ ื“ื™ ืงืฉืจ ืื•ืŸ ืึทืจื™ื™ึทื ืคื™ืจ ืึทืงื˜ื™ื•ื•ืข Directory ื ื™ืฆืขืจืก
ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืžื™ืจ ื“ืึทืจืคึฟืŸ ืึทืงืกืขืก ืฆื• ื“ื™ ืงืึทื ืกืึธื•ืœ ืื•ืŸ ื’ืœื™ื™ึทืš ืฆื• ื“ืขืจ ื˜ืขืงืข multiotp.php, ื ื™ืฆืŸ ื•ื•ืึธืก ืžื™ืจ ื•ื•ืขืœืŸ ืงืึทื ืคื™ื’ื™ืขืจ ืงืฉืจ ืกืขื˜ื˜ื™ื ื’ืก ืฆื• Active Directory.

ื’ื™ื™ืŸ ืฆื• ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ /usr/local/bin/multiotp/ ืื•ืŸ ื“ื•ืจื›ืคื™ืจืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืงืึทืžืึทื ื“ื– ืื™ืŸ ื“ืจื™ื™ึท:

./multiotp.php -config default-request-prefix-pin=0

ื‘ืึทืฉื˜ื™ืžืขืŸ ืฆื™ ืึทืŸ ื ืึธืš (ืฉื˜ืขื ื“ื™ืง) ืฉื˜ื™ืคื˜ ืื™ื– ืคืืจืœืื ื’ื˜ ื•ื•ืขืŸ ืึทืจื™ื™ึทืŸ ืึท ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืฉื˜ื™ืคื˜ (0 ืึธื“ืขืจ 1)

./multiotp.php -config default-request-ldap-pwd=0

ื“ื™ื˜ืขืจืžืึทื ื– ืฆื™ ืึท ืคืขืœื“ ืคึผืึทืจืึธืœ ืื™ื– ืคืืจืœืื ื’ื˜ ื•ื•ืขืŸ ืึทืจื™ื™ึทืŸ ืึท ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืฉื˜ื™ืคื˜ (0 ืึธื“ืขืจ 1)

./multiotp.php -config ldap-server-type=1

ื“ืขืจ ื˜ื™ืคึผ ืคื•ืŸ LDAP ืกืขืจื•ื•ืขืจ ืื™ื– ืื ื’ืขื•ื•ื™ื–ืŸ (0 = ืจืขื’ื•ืœืขืจ LDAP ืกืขืจื•ื•ืขืจ, ืื™ืŸ ืื•ื ื“ื–ืขืจ ืคืึทืœ 1 = ืึทืงื˜ื™ื•ื• Directory)

./multiotp.php -config ldap-cn-identifier="sAMAccountName"

ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ื“ื™ ืคึฟืึธืจืžืึทื˜ ืื™ืŸ ื•ื•ืึธืก ืฆื• ืคืึธืจืฉื˜ืขืœืŸ ื“ืขื ื ืืžืขืŸ (ื“ืขื ื•ื•ืขืจื˜ ื•ื•ืขื˜ ื•ื•ื™ื™ึทื–ืŸ ื‘ืœื•ื™ื– ื“ื™ ื ืึธืžืขืŸ, ืึธืŸ ื“ื™ ืคืขืœื“)

./multiotp.php -config ldap-group-cn-identifier="sAMAccountName"

ื“ื™ ื–ืขืœื‘ืข ื–ืึทืš, ื ืึธืจ ืคึฟืึทืจ ืึท ื’ืจื•ืคึผืข

./multiotp.php -config ldap-group-attribute="memberOf"

ืกืคึผืขืฆื™ืคื™ืฆื™ืจื˜ ืึท ืžืขื˜ืึธื“ ืฆื• ื‘ืึทืฉืœื™ืกืŸ ืฆื™ ืึท ื‘ืึทื ื™ืฆืขืจ ื’ืขื”ืขืจื˜ ืฆื• ืึท ื’ืจื•ืคึผืข

./multiotp.php -config ldap-ssl=1

ื–ืึธืœ ืื™ืš ื ื•ืฆืŸ ืึท ื–ื™ื›ืขืจ ืงืฉืจ ืฆื• ื“ื™ LDAP ืกืขืจื•ื•ืขืจ (ืคื•ืŸ ืงื•ืจืก - ื™ืึธ!)

./multiotp.php -config ldap-port=636

ืคึผืึธืจื˜ ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ื“ื™ LDAP ืกืขืจื•ื•ืขืจ

./multiotp.php -config ldap-domain-controllers=adSRV.domain.local

ื“ื™ื™ืŸ ืึทืงื˜ื™ื•ื•ืข Directory ืกืขืจื•ื•ืขืจ ืึทื“ืจืขืก

./multiotp.php -config ldap-base-dn="CN=Users,DC=domain,DC=local"

ืžื™ืจ ืึธื ื•ื•ื™ื™ึทื–ืŸ ื•ื•ื• ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื–ื•ื›ืŸ ืคึฟืึทืจ ื ื™ืฆืขืจืก ืื™ืŸ ื“ื™ ืคืขืœื“

./multiotp.php -config ldap-bind-dn="[email protected]"

ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ื•ื•ืืก ื”ืื˜ ื–ื•ื›ืŸ ืจืขื›ื˜ ืื™ืŸ ืึทืงื˜ื™ื•ื• Directory

./multiotp.php -config ldap-server-password="MySuperPassword"

ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืคึผืึทืจืึธืœ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• Active Directory

./multiotp.php -config ldap-network-timeout=10

ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ื˜ื™ื™ืžืึทื•ื˜ ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• Active Directory

./multiotp.php -config ldap-time-limit=30

ืžื™ืจ ืฉื˜ืขืœืŸ ืึท ืฆื™ื™ื˜ ืœื™ืžื™ื˜ ืคึฟืึทืจ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืึทืจื™ื™ึทื ืคื™ืจ ืึธืคึผืขืจืึทืฆื™ืข

./multiotp.php -config ldap-activated=1

ืึทืงื˜ืึทื•ื•ื™ื™ื˜ื™ื ื’ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคื•ืŸ Active Directory ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’

./multiotp.php -debug -display-log -ldap-users-sync

ืžื™ืจ ืึทืจื™ื™ึทื ืคื™ืจ ื ื™ืฆืขืจืก ืคื•ืŸ ืึทืงื˜ื™ื•ื• Directory

ืฉืจื™ื˜ 3. ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืึท QR ืงืึธื“ ืคึฟืึทืจ ื“ื™ ืกื™ืžืขืŸ
ืึทืœืฅ ื“ืึธ ืื™ื– ื’ืึธืจ ืคึผืฉื•ื˜. ืขืคึฟืขื ืขืŸ ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืคื•ืŸ ื“ื™ ืึธื˜ืคึผ ืกืขืจื•ื•ืขืจ ืื™ืŸ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ, โ€‹โ€‹ืงืœืึธืฅ ืื™ืŸ (ื˜ืึธืŸ ื ื™ื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ื˜ื•ื™ืฉืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืคึผืึทืจืึธืœ ืคึฟืึทืจ ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ!), ืื•ืŸ ื’ื™ื˜ ื“ื™ "ื“ืจื•ืง" ืงื ืขืคึผืœ:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ืขื ืงืึทืžืฃ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึท ื‘ืœืึทื˜ ื•ื•ืึธืก ื›ึผื•ืœืœ ืฆื•ื•ื™ื™ QR ืงืึธื•ื“ื–. ืžื™ืจ ืžื•ื˜ื™ืง ืื™ื’ื ืึธืจื™ืจืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืคื•ืŸ ื–ื™ื™ (ื˜ืจืึธืฅ ื“ื™ ืึทื˜ืจืึทืงื˜ื™ื•ื• ื™ื ืกืงืจื™ืคึผืฉืึทืŸ Google Authenticator / Authenticator / 2 Steps Authenticator), ืื•ืŸ ื•ื•ื™ื“ืขืจ, ืžื™ืจ ืžื•ื˜ื™ืง ื™ื‘ืขืจืงื•ืงืŸ ื“ื™ ืจื’ืข ืงืึธื“ ืื™ืŸ ืึท ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืกื™ืžืขืŸ ืื•ื™ืฃ ื“ื™ ื˜ืขืœืขืคืึธืŸ:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
(ื™ืึธ, ืื™ืš ื“ื™ืœื™ื‘ืจืึทื˜ ืงืึทืœื™ืข ื“ื™ QR ืงืึธื“ ืฆื• ืžืึทื›ืŸ ืขืก ืึทื ืจื™ื“ืึทื‘ืึทืœ).

ื ืึธืš ืงืึทืžืคึผืœื™ื˜ื™ื ื’ ื“ื™ ืึทืงืฉืึทื ื–, ืึท ื–ืขืงืก-ืฆื™ืคึฟืขืจ ืคึผืึทืจืึธืœ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ืื™ืŸ ื“ื™ื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื™ืขื“ืขืจ ื“ืจื™ื™ืกื™ืง ืกืขืงื•ื ื“ืขืก.

ืฆื• ื–ื™ื™ืŸ ื–ื™ื›ืขืจ, ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืขืก ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื•ื‘ื™ื ื“:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
ื“ื•ืจืš ืึทืจื™ื™ึทืŸ ื“ื™ื™ืŸ ื ืืžืขืŸ ืื•ืŸ ืื™ื™ืŸ ืžืึธืœ ืคึผืึทืจืึธืœ ืคึฟื•ืŸ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ื™ืŸ ื˜ืขืœืขืคืึธืŸ. ื”ืึธื˜ ืื™ืจ ื‘ืึทืงื•ืžืขืŸ ืึท positive ืขื ื˜ืคืขืจ? ืึทื–ื•ื™ ืžื™ืจ ืžืึทืš ืื•ื™ืฃ.

ืฉืจื™ื˜ 4. ื ืึธืš ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืื•ืŸ ื˜ืขืกื˜ื™ื ื’ ืคื•ืŸ FreeRADIUS ืึธืคึผืขืจืึทืฆื™ืข
ื•ื•ื™ ืื™ืš ื“ืขืจืžืื ื˜ ืื•ื™ื‘ืŸ, MultiOTP ืื™ื– ืฉื•ื™ืŸ ืงืึทื ืคื™ื’ื™ืขืจื“ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ FreeRADIUS, ืึทืœืข ื•ื•ืึธืก ื‘ืœื™ื™ื‘ื˜ ืฆื• ืœื•ื™ืคืŸ ื˜ืขืกืฅ ืื•ืŸ ืœื™ื™ื’ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืื•ื ื“ื–ืขืจ VPN ื’ื™ื™ื˜ื•ื•ื™ื™ ืฆื• ื“ื™ FreeRADIUS ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข.

ืžื™ืจ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืฆื• ื“ื™ ืกืขืจื•ื•ืขืจ ืงืึทื ืกืึธื•ืœ, ืฆื• ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ /usr/local/bin/multiotp/, ืึทืจื™ื™ึทืŸ:

./multiotp.php -config debug=1
./multiotp.php -config display-log=1

ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืžืขืจ ื“ื™ื˜ื™ื™ืœื“ ืœืึธื’ื™ื ื’.

ืื™ืŸ ื“ื™ FreeRADIUS ืงืœื™ื™ืึทื ืฅ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข (/etc/freeradius/clinets.conf) ื‘ืึทืžืขืจืงืŸ ืึทืœืข ืฉื•ืจื•ืช ืฉื™ื™ึทื›ื•ืช ืฆื• ืœืึธืงืึทืœื”ืึธืกื˜ ืื•ืŸ ืœื™ื™ื’ ืฆื•ื•ื™ื™ ืื™ื™ื ืกืŸ:

client localhost {
        ipaddr = 127.0.0.1
        secret          = testing321
        require_message_authenticator = no
}

- ืคึฟืึทืจ ืคึผืจื•ื‘ื™ืจืŸ

client 192.168.1.254/32 {
        shortname =     CiscoASA
        secret =        ConnectToRADIUSSecret
}

- ืคึฟืึทืจ ืื•ื ื“ื–ืขืจ VPN ื’ื™ื™ื˜ื•ื•ื™ื™.

ืจื™ืกื˜ืึทืจื˜ FreeRADIUS ืื•ืŸ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ืงืœืึธืฅ ืื™ืŸ:

radtest username 100110 localhost 1812 testing321

ื•ื•ื• ื ืืžืขืŸ = ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ, 100110 = ืคึผืึทืจืึธืœ ื’ืขื’ืขื‘ืŸ ืฆื• ืื•ื ื“ื– ื“ื•ืจืš ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืื•ื™ืฃ ื“ื™ ื˜ืขืœืขืคืึธืŸ, ืœืึธืงืึทืœื”ืึธืกื˜ = RADIUS ืกืขืจื•ื•ืขืจ ืึทื“ืจืขืก, 1812 - RADIUS ืกืขืจื•ื•ืขืจ ืคึผืึธืจื˜, testing321 - RADIUS ืกืขืจื•ื•ืขืจ ืงืœื™ืขื ื˜ ืคึผืึทืจืึธืœ (ื•ื•ืึธืก ืžื™ืจ ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ).

ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ืขื ื‘ืึทืคึฟืขืœ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ื‘ืขืขืจืขืš ื•ื•ื™ ื’ื™ื™ื˜:

Sending Access-Request of id 44 to 127.0.0.1 port 1812
        User-Name = "username"
        User-Password = "100110"
        NAS-IP-Address = 127.0.1.1
        NAS-Port = 1812
        Message-Authenticator = 0x00000000000000000000000000000000
rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=44, length=20

ืื™ืฆื˜ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทื›ืŸ ื–ื™ื›ืขืจ ืึทื– ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ื– ื”ืฆืœื—ื” ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“. ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื“ื™ ืœืึธื’ ืคื•ืŸ ืžื•ืœื˜ื™ืึธื˜ืคึผ ื–ื™ืš:

tail /var/log/multiotp/multiotp.log

ืื•ืŸ ืื•ื™ื‘ ื“ื™ ืœืขืฆื˜ืข ืคึผืึธื–ื™ืฆื™ืข ืื™ื–:

2016-09-01 08:58:17     notice  username  User    OK: User username successfully logged in from 127.0.0.1
2016-09-01 08:58:17     debug           Debug   Debug: 0 OK: Token accepted from 127.0.0.1

ื“ืขืจื ืึธืš ืึทืœืฅ ืื™ื– ื’ื•ื˜ ืื•ืŸ ืžื™ืจ ืงืขื ืขืŸ ืคืึทืจืขื ื“ื™ืงืŸ

ืฉืจื™ื˜ 5: ืงืึทื ืคื™ื’ื™ืขืจ Cisco ASA
ืœืึธืžื™ืจ ืฉื˜ื™ืžืขืŸ ืึทื– ืžื™ืจ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืึท ืงืึทื ืคื™ื’ื™ืขืจื“ ื’ืจื•ืคึผืข ืื•ืŸ ืคึผืึทืœืึทืกื™ื– ืคึฟืึทืจ ืึทืงืกืขืก ื“ื•ืจืš SLL VPN, ืงืึทื ืคื™ื’ื™ืขืจื“ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ืึทืงื˜ื™ื•ื• Directory, ืื•ืŸ ืžื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ื“ืขื ืคึผืจืึธืคื™ืœ.

1. ืœื™ื™ื’ ืึท ื ื™ื™ึทืข AAA ืกืขืจื•ื•ืขืจ ื’ืจื•ืคึผืข:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
2. ืœื™ื™ื’ ืื•ื ื“ื–ืขืจ ืžื•ืœื˜ื™ืึธื˜ืคึผ ืกืขืจื•ื•ืขืจ ืฆื• ื“ืขืจ ื’ืจื•ืคึผืข:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
3. ืžื™ืจ ืจืขื“ืึทื’ื™ืจืŸ ืงืฉืจ ืคึผืจืึธืคื™ืœ, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืึทืงื˜ื™ื•ื•ืข Directory ืกืขืจื•ื•ืขืจ ื’ืจื•ืคึผืข ื•ื•ื™ ื“ื™ ื”ื•ื™ืคึผื˜ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืกืขืจื•ื•ืขืจ:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
4. ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื•ื•ืึทื ืกื™ืจื˜ืข -> ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžื™ืจ ืื•ื™ืš ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ ืึทืงื˜ื™ื•ื•ืข Directory ืกืขืจื•ื•ืขืจ ื’ืจื•ืคึผืข:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
5. ืื™ืŸ ื“ื™ ืงื•ื•ื™ื˜ืœ ืึทื•ื•ืึทื ืกื™ืจื˜ืข -> ืฆื•ื•ื™ื™ื˜ื™ืง ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืื•ื™ืกืงืœื™ื™ึทื‘ืŸ ื“ื™ ื‘ืืฉืืคืŸ ืกืขืจื•ื•ืขืจ ื’ืจื•ืคึผืข ืื™ืŸ ื•ื•ืึธืก ื“ื™ ืžื•ืœื˜ื™ืึธื˜ืคึผ ืกืขืจื•ื•ืขืจ ืื™ื– ืจืขื’ื™ืกื˜ืจื™ืจื˜. ื‘ืึทืžืขืจืงื•ื ื’ ืึทื– ื“ื™ ืกืขืกื™ืข ื ืืžืขืŸ ืื™ื– ื™ื ื›ืขืจืึทื˜ื™ื“ ืคื•ืŸ ื“ื™ ืขืจืฉื˜ื™ืง ืึทืึทืึท ืกืขืจื•ื•ืขืจ ื’ืจื•ืคึผืข:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
ืฆื•ืœื™ื™ื’ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ืื•ืŸ

ืฉืจื™ื˜ 6, ืื•ื™ืš ื“ื™ ืœืขืฆื˜ืข
ืœืึธืžื™ืจ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืื•ื™ื‘ ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืึทืจื‘ืขื˜ ืคึฟืึทืจ SLL VPN:

ื’ื™ื™ืŸ ืฆื• 2FA (ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ASA SSL VPN)
ื•ื•ืึธื™ืœืึท! ื•ื•ืขืŸ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื•ืจืš Cisco AnyConnect VPN ืงืœื™ืขื ื˜, ืื™ืจ ื•ื•ืขื˜ ืื•ื™ืš ื–ื™ื™ืŸ ื’ืขื‘ืขื˜ืŸ ืคึฟืึทืจ ืึท ืฆื•ื•ื™ื™ื˜ ืื™ื™ืŸ-ืฆื™ื™ึทื˜ ืคึผืึทืจืึธืœ.

ืื™ืš ื”ืึธืคึฟืŸ ืึทื– ื“ืขืจ ืึทืจื˜ื™ืงืœ ื•ื•ืขื˜ ื”ืขืœืคึฟืŸ ืขืžืขืฆืขืจ, ืื•ืŸ ืึทื– ืขืก ื•ื•ืขื˜ ื’ืขื‘ืŸ ืขืžืขืฆืขืจ ืฆื• ื˜ืจืึทื›ื˜ืŸ ื•ื•ืขื’ืŸ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ ื“ืขื, ืคืจื™ื™ ืึธื˜ืคึผ ืกืขืจื•ื•ืขืจ, ืคึฟืึทืจ ืื ื“ืขืจืข ื˜ืึทืกืงืก. ื™ื™ึทื ื˜ื™ื™ืœืŸ ืื™ืŸ ื“ื™ ื‘ืึทืžืขืจืงื•ื ื’ืขืŸ ืื•ื™ื‘ ืื™ืจ ื•ื•ื™ืœื˜.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’