<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Off-internet servers on network authenticate via proxy in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878719#M405</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/docs/authproxy-reference#http-proxy-section"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190604i88F0186829D747E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" alt="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/docs/authproxy-reference#http-proxy-section" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" style="width: 690px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#http-proxy-section" target="_blank" rel="noopener"&gt;Authentication Proxy Reference - Duo&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;Ensure simple, secure access to your local services and applications with the Duo Authentication Proxy. Learn more about configuration options for your needs.&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;&lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/cdn_emojis/twitter/slight_smile.png" style="display : inline;" /&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 22 Jun 2022 18:49:22 GMT</pubDate>
    <dc:creator>Amy2</dc:creator>
    <dc:date>2022-06-22T18:49:22Z</dc:date>
    <item>
      <title>Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878714#M400</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;We have installed a DUO proxy on our network that we are using for a variety of devices.  We would like our servers that exist without Internet access to perform MFA via the DUO Proxy server.  The servers and the DUO Proxy server are in the same network.&lt;/P&gt;
&lt;P&gt;Is there documentation for this use case?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 16 Jun 2022 21:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878714#M400</guid>
      <dc:creator>pcs.dwjacobs</dc:creator>
      <dc:date>2022-06-16T21:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878715#M401</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi &lt;A class="mention" href="https://community.duo.com/u/pcs.dwjacobs"&gt;@pcs.dwjacobs&lt;/A&gt;, welcome to the Duo Community! Thanks for sharing your question here with us. I understand that you’d like to use the Duo Authentication Proxy to authenticate for your servers without internet access, which are in the same network as the Auth Proxy.&lt;/P&gt;
&lt;P&gt;There is a use case that might work for this, which sort of addresses what you are trying to accomplish. The Auth Proxy can be set up to act as an http proxy, but &lt;EM&gt;only&lt;/EM&gt; for traffic to Duo.&lt;BR /&gt;
The primary use case is when you have something like Duo Unix or an auth API integration set up on a server without internet access. With this configuration, API calls to Duo can be proxied through the Auth Proxy. The Auth Proxy itself would need to be able to reach Duo over the internet to complete authentication though. Here is the documentation for that: &lt;A href="https://duo.com/docs/authproxy-reference#http-proxy-section" class="inline-onebox"&gt;Authentication Proxy Reference - Duo | Duo Security&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Since the &lt;A href="https://duo.com/docs/authproxy-reference#:~:text=The%20Authentication%20Proxy%20communicates%20with%20Duo%27s%20service%20on%20TCP%20port%20443."&gt;Authentication Proxy communicates with Duo’s service on TCP Port 443&lt;/A&gt;, the Auth Proxy must always be able to reach the internet in order to complete multi-factor authentication.&lt;BR /&gt;
I hope that helps!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878715#M401</guid>
      <dc:creator>Amy2</dc:creator>
      <dc:date>2022-06-22T14:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878716#M402</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Amy,&lt;/P&gt;
&lt;P&gt;Thanks for your response. To reduce or vulnerability risks, we typically keep some Windows servers off the Internet entirely. They get licensing from a Microsoft KMS server and Windows patches from WSUS. We already have a Duo Auth Proxy on the network that we use for MFA with network appliances. The Duo Auth Proxy is connected to the Internet.&lt;/P&gt;
&lt;P&gt;Another MFA product our company uses has an a network server that proxies authentication out to the Internet. We were considering replacing that product with Duo, but cannot until we resolve this problem.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" style="width: 258px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191280iE485997ABC3C3AFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" alt="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" style="width: 178px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191424iDD6FA96424248EB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" alt="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jun 2022 15:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878716#M402</guid>
      <dc:creator>pcs.dwjacobs</dc:creator>
      <dc:date>2022-06-22T15:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878717#M403</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Thank you for providing some more context! That definitely makes sense.&lt;/P&gt;
&lt;ASIDE class="quote no-group" data-username="pcs.dwjacobs" data-post="3" data-topic="12460"&gt;
&lt;DIV class="title"&gt;
&lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
&lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/letters/p_7993a0.png" style="display : inline;" /&gt; pcs.dwjacobs:&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;The Duo Auth Proxy is connected to the Internet.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;
&lt;P&gt;In that case, the above documentation I linked should work for this! Let me know if you have additional questions, and I can loop one of our team members in to help.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jun 2022 16:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878717#M403</guid>
      <dc:creator>Amy2</dc:creator>
      <dc:date>2022-06-22T16:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878718#M404</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Amy,&lt;/P&gt;
&lt;P&gt;Thanks. I do not see a link. Perhaps it got stripped off?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" style="width: 258px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191280iE485997ABC3C3AFE/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" alt="2X_5_5405953d8d6abe1ae201c9716132ed5c4b3b629f.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" style="width: 178px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191424iDD6FA96424248EB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" alt="2X_a_a7462d8032b3c64183cba9814baf6141196c6bcd.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jun 2022 18:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878718#M404</guid>
      <dc:creator>pcs.dwjacobs</dc:creator>
      <dc:date>2022-06-22T18:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Off-internet servers on network authenticate via proxy</title>
      <link>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878719#M405</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;ASIDE class="onebox allowlistedgeneric" data-onebox-src="https://duo.com/docs/authproxy-reference#http-proxy-section"&gt;
  &lt;HEADER class="source"&gt;
      &lt;span class="lia-inline-image-display-wrapper" image-alt="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" style="width: 32px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/190604i88F0186829D747E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" alt="2X_2_2808153faec36abf493f2c2d8ad8d69c65f0bdc7.png" /&gt;&lt;/span&gt;

      &lt;A href="https://duo.com/docs/authproxy-reference#http-proxy-section" target="_blank" rel="noopener"&gt;Duo Security&lt;/A&gt;
  &lt;/HEADER&gt;

  &lt;ARTICLE class="onebox-body"&gt;
    &lt;DIV class="aspect-image" style="--aspect-ratio:690/362;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" style="width: 690px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191267i2802AA91D1A88FF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" alt="1X_59aa89a0f991dff07b1e7f1cea48969c74b194fa.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;

&lt;H3&gt;&lt;A href="https://duo.com/docs/authproxy-reference#http-proxy-section" target="_blank" rel="noopener"&gt;Authentication Proxy Reference - Duo&lt;/A&gt;&lt;/H3&gt;

  &lt;P&gt;Ensure simple, secure access to your local services and applications with the Duo Authentication Proxy. Learn more about configuration options for your needs.&lt;/P&gt;


  &lt;/ARTICLE&gt;

  &lt;DIV class="onebox-metadata"&gt;
    
    
  &lt;/DIV&gt;

  &lt;DIV style="clear: both"&gt;&lt;/DIV&gt;
&lt;/ASIDE&gt;

&lt;P&gt;&lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/cdn_emojis/twitter/slight_smile.png" style="display : inline;" /&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Jun 2022 18:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/off-internet-servers-on-network-authenticate-via-proxy/m-p/4878719#M405</guid>
      <dc:creator>Amy2</dc:creator>
      <dc:date>2022-06-22T18:49:22Z</dc:date>
    </item>
  </channel>
</rss>

