11-06-2024 05:21 PM
Hi,
Good day!
I am looking for Configuration and Documentation on how to enable MFA on Cisco 3850 and 2960 switch. Anyone here can help and share string of commands on how to configure MFA on Cisco 3850 and 2960. This is for the secondary authentication for Cisco SSH management login. We are using Deepnet specifically for the MFA. Thank you in advance.
11-06-2024 05:59 PM
Deepnet doesn't have integration to Cisco IOS for 2 factor authentication. We are now looking for DUO configuration and setup.
11-08-2024 10:04 AM
This for device Admin or for endpoint access ??
MHM
11-06-2024 10:13 PM
Hello!
You won't be able to enable MFA directly, you will have to go through an AAA server like ISE.
BR
11-07-2024 02:04 PM
Hi @DanielP211 Thank you so much for the Response I will take a look on the ISE and see if we can have that in our network.
11-07-2024 06:36 AM
As @DanielP211 mentioned, the switches themselves do not support MFA so we have to rely on an authentication/authorization server such as ISE or even Microsoft NPS. On MS NPS you can only use RADIUS however with products like ISE you can use RADIUS or TACACS. TACACS have much more pros compared to RADIUS when it comes devices management, however, if you don't have very restrictive policies then RADIUS could be a good solution for this. Take a look please at this post of mine that shows how to configure device management accesses via RADIUS on ISE:
11-07-2024 02:06 PM
Hi @Aref Alsouqi Thank you so much for your response I will look in to your post and see if we can have this in our network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide