cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6010
Views
0
Helpful
3
Replies

Cisco ASA 2FA(one time password) authentication

daredavil82
Level 1
Level 1

I would like to inquire cisco ASA do support 2FA( second factor authentication-example: One time password) or not?. Just to inform, I want configure my cisco ASA to authenticate vpn user using Active directory password and One time password as well. Currently my cisco ASA authenticating vpn users using active directory credential and assigning this user with particular IP went they login into VPN. I have created many group in active directory. Each of these group will assigned with different IP went they login into VPN.  All these setting already in the cisco ASA. Let said if I impose 2FA authentication in my vpn later, it will affect my current setting in Cisco ASA or not? Would I still able to assign this group with different IP? Do I need to change my current setting in cisco or active directory in order to deploy this second factor authentication??

Any help highly appreaciated..

3 Replies 3

Bastien Migette
Cisco Employee
Cisco Employee

Hello,

You can configure double authentication as described here:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/vpngrp.html#wp1243545

but it only work for clientless/anyconnect vpn, see the releases notes:

http://www.cisco.com/en/US/docs/security/asa/asa82/release/notes/asarn82.html#wp424773

I hope this help.

Dear Bmigette

I have a requirement to integrate the Cisco VPN (Cisco VPN Client for Remote Access IPSec VPNs etc.) with OTP system (One Time Password) only.

I already have OTP system deployed in my network. And i already have remote access VPN configured on the ASA , now i have a requirement to integrate users which are using Remote access VPN to integrate with currently deployed OTP system. I want to know what configuration needs to be done on the ASA.

Appreciate your response on this.

Farooq Razzaque
Level 1
Level 1

Dear Daredavil

Are u able to authenticate your ASA's VPN with second Factor authentication ?

I also have requirement to integrate ASA VPN with One Time Password (OTP) only.