5.2

Table Of Contents
6 For RADIUS authentication, complete the rest of the fields:
a Select Use
the same username and password for RADIUS and Windows authentication if the initial
RADIUS authentication uses Windows authentication that triggers an out-of-band transmission of a
token code, and this token code is used as part of a RADIUS challenge.
If you select this check box, users will not be prompted for Windows credentials after RADIUS
authentication if the RADIUS authentication uses the Windows username and password. Users do
not have to reenter the Windows username and password after RADIUS authentication.
b From the Authenticator drop-down list, select Create New Authenticator and complete the page.
n
Set Accounting port to 0 unless you want to enable RADIUS accounting. Set this port to a non-
zero number only if your RADIUS server supports collecting accounting data. If the RADIUS
server does not support accounting messages and you set this port to a nonzero number, the
messages will be sent and ignored and retried a number of times, resulting in a delay in
authentication.
Accounting data can be used in order to bill users based on usage time and data. Accounting
data can also be used for statistical purposes and for general network monitoring.
n
If you specify a realm prefix string, the string is placed at the beginning of the username when
it is sent to the RADIUS server. For example, if the username entered in the View Client is jdoe
and the realm prefix DOMAIN-A\ is specified, the username DOMAIN-A\jdoe is sent to the RADIUS
server. Similarly if you use the realm suffix, or postfix, string @mycorp.com, the username
jdoe@mycorp.com is sent to the RADIUS server.
7 Click OK to save your changes.
You do not need to restart the View Connection Server service. The necessary configuration files are
distributed automatically and the configuration settings take effect immediately.
When users open View Client and authenticate to View Connection Server, they are prompted for two-factor
authentication. For RADIUS authentication, the login dialog box displays text prompts that contain the token
label you specified.
What to do next
If you have a replicated group of View Connection Server instances and you want to also set up RADIUS
authentication on them, you can re-use an existing RADIUS authenticator configuration.
Troubleshooting RSA SecurID Access Denial
Access is denied when View Client connects with RSA SecurID authentication.
Problem
A View Client connection with RSA SecurID displays Access Denied and the RSA Authentication Manager
Log Monitor displays the error Node Verification Failed.
Cause
The RSA Agent host node secret needs to be reset.
Solution
1 In View Administrator, select View Configuration > Servers.
2 In View Connection Servers, select the View Connection Server and click Edit.
3 On the Authentication tab, select Clear node secret.
4 Click OK to clear the node secret.
Chapter 7 Setting Up User Authentication
VMware, Inc. 171