Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.95
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Adding User")}}

Adding User

{{ $t('productDocDetail.updateTime') }}: 2025-12-25
  1. Click Add and select User to enter the Add User page, as shown in the figure below:

A screenshot of a computer

Description automatically generated

  1. Configure the Basic Attributes of the user. The following are the basic attributes:

Name: Enter a name for this user. This field is required.

Description: Enter a brief description for this user.

Password: Enter the password of this user account.

Mobile Number: Enter the mobile phone number of the user.

Added To: Specify to which user group this user is added.

Inherit authentication settings from parent group: If selected, the current user will inherit its parent group's policy set and authentication settings. If not selected, the authentication settings and policy set could differ from those of its parent group.

Virtual IP Assignment: To set the way users get virtual IP.

  1. Configure the valid time of the user account.

Expire indicates the date on which this user account will get invalid. If Never expire is selected, the user account will always be valid. If the On date is selected, select the date as the expiry date.

  1. Configure the Status of the user account. This user account will be enabled (valid) if the Enabled is selected or disabled (invalid) if Disabled is selected.
  2. Configure Authentication Options.

Public user: Indicate that multiple users can use the user account to access SSL VPN concurrently.

Private user: Indicate that only one user can use the user account to log in to the SSL VPN at a time. If a second user uses this user account to connect to SSL VPN, the previous user will be forced to log out.

Primary Authentication: Indicate the authentication method(s) that is (are) first applied to verify users when they log in to the SSL VPN. If any secondary authentication method is selected, primary authentication will be followed by secondary authentication when the users log in to the SSL VPN. By default, it is a Local password.

Local password: The connecting users need to pass local password-based authentication using the SSL VPN account in this user group.

Secondary Authentication: Secondary authentication is an optional and supplementary authentication method. Select it to require the connecting users to submit the corresponding credentials after passing the primary authentication(s), enhancing security in SSL VPN access.

Hardware ID: This is the unique identifier of a client-end computer. Each computer comprises some hardware components, such as NIC, hard disk, etc., which are unquestionably identified by their features that cannot be forged. SSL VPN client software can extract the features of some terminal hardware components and consequently generate the hardware ID. This hardware ID should be submitted to the Sangfor device and bound to the corresponding user account. Once the administrator approves the submitted hardware ID, the user can pass hardware ID-based authentication when accessing SSL VPN through a specified terminal(s). This authentication method helps to eliminate potential unauthorized access. As mentioned above, multiple users could use the same user account (public user account) to access SSL VPN concurrently. It is reasonable that a user account may bind to more than one hardware ID. That also means an end-user can use one account to log in to SSL VPN through different endpoints, as long as the user account is binding to the hardware IDs submitted by the user from those endpoints.

  1. Assign Roles to a user group.

Click the Roles field to enter the Assigned Roles page, as shown below:

A screenshot of a computer

Description automatically generated

Click Add to enter the Select Role page, as shown below:

A screenshot of a web browser

Description automatically generated

Select the checkbox next to the desired roles and click the OK button. The roles are added to the Assigned Roles page.

Click the OK button and name the assigned roles filled in the Roles field.

If the desired role is not found in the list, click Create + Associate to create a new role and associate with the user group. (The procedures of creating a role are the same as that in the Roles Adding section).

To remove a role from the list, select the role and click Delete.

To edit a role, select the role and click Edit.