<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Flow Authentication through an ASA using Google Authenticato in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244559#M594070</link>
    <description>&lt;P&gt;Yes SAML if they have a IDP, otherwise you have to use radius with google authenticator.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2025 21:22:10 GMT</pubDate>
    <dc:creator>ccieexpert</dc:creator>
    <dc:date>2025-01-07T21:22:10Z</dc:date>
    <item>
      <title>HTTPS Flow Authentication through an ASA using Google Authenticator</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244432#M594061</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;We are looking to set up on Cisco ASA the following flow.&lt;/P&gt;&lt;P&gt;We are using ssl vpn, and wanted to enforce new connections in from the outside using AAA, and sending the authentication request from the ASA to a back end server running RADUIS and using Google authenticator to provide 2FA for new connections.&lt;/P&gt;&lt;P&gt;Just looking for some guidance as to whether this is possible and whether anyone else has set up something similar.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 15:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244432#M594061</guid>
      <dc:creator>jamesholley</dc:creator>
      <dc:date>2025-01-07T15:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244440#M594062</link>
      <description>&lt;P&gt;Yes it is possible. The big question is what is your identity source ? where do you have the users defined ? If you have MS365/ENTRA, then it comes with free MS authenticator, then i would go that path.. or another identity source, it may be best to use that, unless you want to create each user on the radius server and enable 2FA.. i have done it with freeradius and google authenticator.&lt;/P&gt;
&lt;P&gt;Here is a example :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://networkjutsu.com/freeradius-google-authenticator/" target="_blank"&gt;https://networkjutsu.com/freeradius-google-authenticator/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;he has a article for newer version 3.x of freeradius...&lt;/P&gt;
&lt;P&gt;i would not recommend it unless you have no other identity source such as Entra/Azure or google workspace or any other identity source that has MFA capabilities.&lt;/P&gt;
&lt;P&gt;**If that was useful , Please rate as helpful**&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 16:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244440#M594062</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-07T16:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244551#M594068</link>
      <description>&lt;P&gt;Yes but why not use SAML?&amp;nbsp; Why use RADIUS at all here?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 21:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244551#M594068</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-07T21:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244559#M594070</link>
      <description>&lt;P&gt;Yes SAML if they have a IDP, otherwise you have to use radius with google authenticator.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 21:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244559#M594070</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-07T21:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244833#M594083</link>
      <description>&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001256?amp=1" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001256?amp=1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Check this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 16:33:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244833#M594083</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-08T16:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244922#M594085</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I can confirm that this worked, we don't have any other option to use any IDP so RADIUS &amp;amp; GAuth is all we can use as far as I can see..&lt;/P&gt;&lt;P&gt;Thanks PeteNet but we are not using AnyConnect&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 20:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244922#M594085</guid>
      <dc:creator>MadAxeman1</dc:creator>
      <dc:date>2025-01-08T20:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Flow Authentication through an ASA using Google Authenticato</title>
      <link>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244946#M594089</link>
      <description>&lt;P&gt;ok you didnt answer my questions.. where are the users today ? are they on on prem AD or somewhere else ? radius and google auth by itself will require you to create users locally which is ok, but i assume you already have another identity source right ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 22:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/https-flow-authentication-through-an-asa-using-google/m-p/5244946#M594089</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2025-01-08T22:10:17Z</dc:date>
    </item>
  </channel>
</rss>

