cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
222
Views
0
Helpful
1
Replies

Configuring OTP via DUO

Javanshir
Level 1
Level 1

Hello 

 We have ISE and FTD for vpn users. And we want to configure OTP via DUO. After Configuration we found that user is not checking in ISE. We try with incorrect password and disabled user but were able to connect using OTP. Looks like user account passes through ISE without checking.

1 Reply 1

Could you give some information about how you have set this up, and the authentication traffic flow?

Ideally the FTD should be authenticating to the ISE, and the ISE is using DUO authentication proxy, and DUO will be authenticating the username / password against the AD server and as well as send OTP before returning a verdict to ISE.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card