Prior to the installation of the Before you install the DualShield MFA serversystem, you must prepare the following items:
...
your environment and plan for choices that you will make during the installation process.
To prepare for installation:
1. A Windows or Linux server machine (virtual or real machine) with 8GM RAM, 4-core CPU, and 10GB free disk space
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
2. An FQDN for your DualShield MFA server consoles, e.g. mfa.acme.com
| Info |
|---|
The DualShield server includes 4 web consoles
If you do not plan to make your DualShield MFA server consoles accessible from the public network, then the FQDN can be an internal domain name. However, if you do plan to make one or some of your Dualshield server consoles accessible from the public network, then the FQDN must be an external domain name. Note: You can change the FQDN later after the MFA server installation. |
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
3. An SSL certificate for your DualShield MFA server consoles in a PFX file (a wildcard certificate is acceptable, e.g. *.acme.com)
...
If you need to purchase an SSL certificate from a certificate authority such as GoDaddy, you can use the Deepnet CSR tool
...
Note: You can ask the MFA server installer to generate and use a self-signed SSL certificate. You can also change the server certificate after the MFA server installation.
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
4. An AD service account
...
for the connection between your MFA server and AD server. For a quick start, you can use an existing domain admin or domain user account. Or, you can create a new service account with the appropriate privileges
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
5. (Optional) An AD user group for MFA
...
- Push Authentication
- Self-Services such as downloading MobileID tokens, activating DeviceID tokens, etc.
- SAML integration with external cloud services such as Office 465, SalesForce, Zoom, etc.
enforcement
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
6. (Optional) An SQL service account
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
7. (Optional) Configure corporate firewall
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|
8. Download the DualShield server software
...
, and save it on your DualShield MFA server machine
...
For more details, please check out the following articles:
...
| Expand | ||||||
|---|---|---|---|---|---|---|
| ||||||
|