How to configure iKeys with the iKey Manager


Introduction

iKeys are identity tokens that can be used with Eicon VPN Clients for source authentication. This guide describes how you configure a Master iKey and, once this iKey is configured, how you configure one or more User iKeys. The iKey Manager program is used when configuring both types of iKeys.

Note: With the iKey Manager you may later reset any iKey by inserting it in a USB port, right-clicking on the desired icon, and selecting 'Reset iKey'. Important: If you reset the Master iKey, you will disable management of any User iKey configured with that particular Master iKey - unless you have created a copy.


Prerequisites


Configuring the Master iKey

  1. Insert an iKey in a USB port on the workstation.

    iKey

  2. Open the Eicon iKey Manager program from the Windows 'Start' menu. The iKey Manager will detect the iKey and show it in the window as 'New' with a purple icon.

    iKey Manager

  3. You first need to configure a Master iKey. Right-click the 'New' entry and select 'Create Master iKey'.
    Enter a 'Master Password' and re-enter it for verification.
    The password allows you to access the Master iKey. It should be at least 5 characters long.
    Enter a 'Default PIN' code (min. 4 and max. 8 digits).
    You will use this PIN code when configuring each User iKey associated with this Master iKey. Remote users will also need to enter the default PIN code when using their User iKeys with the VPN Client for the first time.
    Enter a 'Temporary Key'.
    The temporary key must be the same for all remote clients using hard token (iKey) authentication.
    Enter a 'Unique Name'.
    This name is simply used to identify the Master iKey when listed in the iKey Manager.
    Click 'OK'.

    Configure master iKey

  4. In order for the iKey Manager to add the Master iKey to the list, you need to enter the Master Password that you specified above.

    Password

  5. In the list you will see that the Master iKey is now configured. It appears with a yellow icon in a yellow square. Leave the Master iKey in the USB port, as you will need it when configuring User iKeys for your Eicon VPN Client users.

    Master iKey configured

  6. It is recommended that you create a copy of the Master iKey. Otherwise, if the Master iKey is misplaced or reset, you are not able to manage User iKeys that are associated with this iKey.
    Insert a second iKey in another USB port. On the iKey Manager list, right-click on the original Master iKey (yellow square icon) and select 'Copy Master iKey'. The icon of the second key will now change to yellow, but without the yellow square.

    Copy of master iKey

  7. Remove the copy of the Master iKey from the USB port and store it in a safe place.

    If you see this icon at the bottom right of the Windows taskbar, first right-click the icon and select 'Unplug or eject hardware'. Follow the on-screen instructions. Remove the copy Master iKey from the USB port, when you are informed that it is safe to do so.

Configuring the User iKeys

  1. With the Master iKey still inserted in a USB port, insert a new iKey in another USB port. The new iKey appears on the iKey Manager list with a purple icon. Right-click it and select 'Create User iKey'.

    New iKey added

  2. Browse for the configuration file (it has the extension .tok) that has been created for the user in Safepipe's Client section. Select the file and click 'Open'.

    This configuration file contains information necessary for the remote user to configure an Eicon VPN Client.

    Browse for .tok file

  3. The User iKey has now been loaded with the token information and appears on the list with a green icon and the name specified in the token.

    User iKey configured

  4. Remove the User iKey from the USB port.

    If you see this icon at the bottom right of the Windows taskbar, first right-click the icon and select 'Unplug or eject hardware'. Follow the on-screen instructions. Remove the iKey from the USB port, when you are informed that it is safe to do so.

  5. To configure any other User iKey, repeat Steps 1 - 4.

  6. Remove the Master iKey from the USB port.

    If you see this icon at the bottom right of the Windows taskbar, first right-click the icon and select 'Unplug or eject hardware'. Follow the on-screen instructions. Remove the iKey from the USB port, when you are informed that it is safe to do so.

  7. Each User iKey must be handed over to the remote user together with the PIN code.

  8. Now that the User iKeys are configured, the VPN Client can be installed and configured on the users' computers.