11-27-2023 07:30 AM
Hello,
We have users connecting through the VPN (SSL VPN) with the any connect client. I'm asked to look at possible solutions to add an MFA authentication.
Currently, users log into the VPN with their LDAP account.
the ASA queries an internal radius server (NPS) which links with our LDAP (Windows Active Directory) server.
Is there a solution integrated into the ASA? If not, what are the possible solutions?
11-27-2023 08:50 AM
You can use Azure MFA as below guide :
https://cloudexchangers.com/configuring-azure-mfa-for-cisco-vpn-using-the-nps-server/
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension-vpn
Good videos :
11-28-2023 01:10 AM
11-28-2023 01:29 AM
Any MFA option will require a third party product. The most common ones are cloud-hosted (Cisco Duo, Microsoft Entra ID with Authenticator, Okta, etc. - those are probably 90% of the market). A few are available in self-hosted options (RSA SecureID come to mind).
11-28-2023 08:30 AM
Not that i am aware any MFA on prem - even they are on prem, they going to some connector to Cloud
Like example Safenet. you can build own MFA using some opensource (long way to go)
11-28-2023 09:50 AM
11-30-2023 12:33 AM
thank you for your answers, I will study these solutions, I will probably come back later to ask questions
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide