<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2-Factor Strong Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882225#M5482</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're looking for two-factor authentication,&lt;/P&gt;&lt;P&gt;I strongly recommend RSA SecurID.  That's the&lt;/P&gt;&lt;P&gt;best two factor authentication, imho.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something you have &amp;amp; something you know = two-factor authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Nov 2007 21:48:14 GMT</pubDate>
    <dc:creator>kevin.jones1</dc:creator>
    <dc:date>2007-11-26T21:48:14Z</dc:date>
    <item>
      <title>2-Factor Strong Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882224#M5481</link>
      <description>&lt;P&gt;We are in the process of implementing two factor VPN authentication using WIKID but we are having issues, specifically with our ACS. I use the ACS with the Cisco Remote Agent to provide VPN authentication based on AD. The problem is that I would need the ACS to proxy to my WIKID server to authenticate the PIN. I can setup my VPNSM to radius directly to the WIKID server but then I lose all the grouping and IP parameters I apply to users. On top of that, I would have to go  to two places to setup/deactivate a new/terminated employee. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically, is there a way for me to use my ACS for Authorization (via Cisco Remote Agent) and forward the username and PIN to the WIKID server for authentication? &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882224#M5481</guid>
      <dc:creator>mpipkin</dc:creator>
      <dc:date>2020-02-21T18:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: 2-Factor Strong Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882225#M5482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're looking for two-factor authentication,&lt;/P&gt;&lt;P&gt;I strongly recommend RSA SecurID.  That's the&lt;/P&gt;&lt;P&gt;best two factor authentication, imho.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something you have &amp;amp; something you know = two-factor authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2007 21:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882225#M5482</guid>
      <dc:creator>kevin.jones1</dc:creator>
      <dc:date>2007-11-26T21:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2-Factor Strong Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882226#M5483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you can setup your VPN to authenticate using RADIUS to the WIKID server, then you should be able to configure ACS to use RADIUS as an external user database (I believe you'd set it up as a RADIUS Token Server).  ACS won't be able to directly see AD, but that is ok because the WIKID should take care of that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as the WIKID RADIUS supports Cisco AV Pairs as a reply attribute, you can configure it to return the appropriate ACS group mapping.  See &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/qg.html#wp940932" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/qg.html#wp940932&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By setting it up as a RADIUS Token Server, you no longer need the Cisco Remote Agent.  If you are running ACS 4.x, you may want to also look at configuring a Network Access Profile if you need to configure more flexibility in your external database searching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 17:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2-factor-strong-authentication/m-p/882226#M5483</guid>
      <dc:creator>Michael Odom</dc:creator>
      <dc:date>2007-11-28T17:37:41Z</dc:date>
    </item>
  </channel>
</rss>

