<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Request for 2fa authentication. in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881915#M813</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;How are you configured for the FTD VPN?  Are you using RADIUS, SSO, LDAP, or some other method of integration?&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 15 Sep 2022 12:13:39 GMT</pubDate>
    <dc:creator>ktfoster</dc:creator>
    <dc:date>2022-09-15T12:13:39Z</dc:date>
    <item>
      <title>Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881912#M810</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;2FA has been configured for Cisco Firepower Threat Defense VPN. Users connect through Cisco AnyConnect. 2FA is not stable. Sometimes it prompts the 2FA method and sometimes it doesn’t. How to make it keep asking for 2FA?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Sep 2022 14:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881912#M810</guid>
      <dc:creator>slusarj23</dc:creator>
      <dc:date>2022-09-14T14:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881913#M811</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hello &lt;A class="mention" href="https://community.duo.com/u/slusarj23"&gt;@slusarj23&lt;/A&gt;, welcome to the Duo Community!&lt;/P&gt;
&lt;P&gt;I’m sorry to hear you’re having issues with Duo 2FA. Are your users not being prompted to complete 2FA at all, or are you having issues with users receiving push notifications?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Sep 2022 20:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881913#M811</guid>
      <dc:creator>ldubravec</dc:creator>
      <dc:date>2022-09-14T20:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881914#M812</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Good day. For example, out of ten user authentication attempts, the 2fa push notification appears only eight. AnyConnect doesn’t always fail with 2fa. I want it to ask for 2fa from the user every time.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Sep 2022 07:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881914#M812</guid>
      <dc:creator>slusarj23</dc:creator>
      <dc:date>2022-09-15T07:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881915#M813</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;How are you configured for the FTD VPN?  Are you using RADIUS, SSO, LDAP, or some other method of integration?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Sep 2022 12:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881915#M813</guid>
      <dc:creator>ktfoster</dc:creator>
      <dc:date>2022-09-15T12:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881916#M814</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="lightbox-wrapper"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2X_8_80713b021a9f236eecafad8fb97cd00d12ee91c8.png" style="width: 690px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/191066i000AF99AF0E21115/image-size/large?v=v2&amp;amp;px=999" role="button" title="2X_8_80713b021a9f236eecafad8fb97cd00d12ee91c8.png" alt="2X_8_80713b021a9f236eecafad8fb97cd00d12ee91c8.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;BR /&gt;
My organization chart&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 16 Sep 2022 07:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881916#M814</guid>
      <dc:creator>slusarj23</dc:creator>
      <dc:date>2022-09-16T07:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Request for 2fa authentication.</title>
      <link>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881917#M815</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;ASIDE class="quote no-group" data-username="slusarj23" data-post="3" data-topic="13060"&gt;
&lt;DIV class="title"&gt;
&lt;DIV class="quote-controls"&gt;&lt;/DIV&gt;
&lt;IMG width="20" height="20" src="https://community.cisco.com/legacyfs/online/ciscoduo/avatar_quotes/slusarj23.png" style="display : inline;" /&gt; slusarj23:&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;For example, out of ten user authentication attempts, the 2fa push notification appears only eight. AnyConnect doesn’t always fail with 2fa. I want it to ask for 2fa from the user every time.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/ASIDE&gt;
&lt;P&gt;Do you mean eight out of ten times a given user gets the Duo Push request to approve, and the other two times the user does not receive the Duo Push request and the VPN login attempt fails? If so, you may want to explore the suggestions in these Duo Push troubleshooting articles:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.duo.com/s/article/2051"&gt;Troubleshooting Duo Push notification issues on iOS devices &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.duo.com/s/article/2050"&gt;Troubleshooting Duo Push notification issues on Android devices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Do you mean that out of ten users, eight of them have to use Duo 2FA to log in and the other two get connected to the VPN with no 2FA at all? That sounds more like a configuration issue and I would encourage you to contact &lt;A href="https://duo.com/support"&gt;Duo Support&lt;/A&gt; to perform more in-depth troubleshooting.&lt;/P&gt;
&lt;P&gt;Since you are using a RADIUS configuration you can &lt;A href="https://help.duo.com/s/article/1126"&gt;enable debug logging at the Duo Authentication Proxy&lt;/A&gt; to see what is happening during an login attempt… does it show a push request sent to the user that then times out with no response, does it allow the user due to policy or status permitting login without 2FA, etc.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 21 Sep 2022 13:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/request-for-2fa-authentication/m-p/4881917#M815</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2022-09-21T13:12:57Z</dc:date>
    </item>
  </channel>
</rss>

