<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo authentication with local user database Sophos XG in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881610#M754</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;CODE&gt;radius_ip_1&lt;/CODE&gt; would be the IP address of the device sending an authentication request to the Duo proxy, so it would be the XG’s IP, and &lt;CODE&gt;radius_secret_1&lt;/CODE&gt; would be the secret shared with the XG in all RADIUS configurations.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Fri, 09 Apr 2021 12:26:54 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2021-04-09T12:26:54Z</dc:date>
    <item>
      <title>Duo authentication with local user database Sophos XG</title>
      <link>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881607#M751</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;hello everyone , i would like to know if it is possible to implement Duo authentication proxy to authenticate with local user database in sophos xg appliance instead active directory and radius server.&lt;/P&gt;
&lt;P&gt;regards,&lt;BR /&gt;
ernof&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 08 Apr 2021 11:41:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881607#M751</guid>
      <dc:creator>er_nof</dc:creator>
      <dc:date>2021-04-08T11:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Duo authentication with local user database Sophos XG</title>
      <link>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881608#M752</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;No, there is no way to point the Duo Authentication Proxy to your local Sophos XG user database for primary authentication.&lt;/P&gt;
&lt;P&gt;What is possible though, if the Sophos XG supports chained authenticators (so you could have separate primary and secondary authentication, and success for the first is required before it will move on to the second), is to point primary authentication to your local database and then add the Duo proxy as a RADIUS server for secondary authentication only with &lt;A href="https://duo.com/docs/authproxy-reference#radius-duo-only"&gt;the &lt;CODE&gt;[radius_server_duo_only]&lt;/CODE&gt; configuration&lt;/A&gt;. In this configuration the Duo proxy only performs 2FA.&lt;/P&gt;
&lt;P&gt;It isn’t clear if the XG can support this though. Looking &lt;A href="https://docs.sophos.com/nsg/sophos-firewall/17.5/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/AuthenticationServices.html"&gt;here&lt;/A&gt; it says “When more than one server is selected, the authentication request is forwarded in the order indicated.” which could mean it isn’t chaining authentication servers, but that it will try the servers until one works, and then stop. Verify the authentication server capabilities of the XG with Sophos.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 08 Apr 2021 14:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881608#M752</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2021-04-08T14:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Duo authentication with local user database Sophos XG</title>
      <link>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881609#M753</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hi DuoKristina,&lt;/P&gt;
&lt;P&gt;Thank you for the confirmation and  i will check if my customer’s sophos xg support  chained authenticator or not. Fyi, my customer need duo to add authentication for sslvpn access&lt;/P&gt;
&lt;P&gt;Under radius_server_duo_only configuration, i still confused what value should i input  at radius_ip_1 and radius_secret_1. For radius_ip_1, is it correct if I put the ip address of the user who is allowed sslvpn access?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Apr 2021 11:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881609#M753</guid>
      <dc:creator>er_nof</dc:creator>
      <dc:date>2021-04-09T11:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Duo authentication with local user database Sophos XG</title>
      <link>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881610#M754</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;CODE&gt;radius_ip_1&lt;/CODE&gt; would be the IP address of the device sending an authentication request to the Duo proxy, so it would be the XG’s IP, and &lt;CODE&gt;radius_secret_1&lt;/CODE&gt; would be the secret shared with the XG in all RADIUS configurations.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/duo-authentication-with-local-user-database-sophos-xg/m-p/4881610#M754</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2021-04-09T12:26:54Z</dc:date>
    </item>
  </channel>
</rss>

