03-12-2022 05:32 PM
03-12-2022 07:17 PM - edited 03-12-2022 07:22 PM
I really do not understand why anyone would want to make this process so complicated.
Get a RADIUS server and create several tiered "network" accounts and put them into a "special" group.
Only those who have the "needs" to log into are given access to log into network equipment (i.e, Finance and Shipping people do not need to have "admin" access nor a requirement to log into network equipment).
Passwords needs to be complicated and regularly changed.
If someone really wants to do 2FA/MFA, the RADIUS server is where 2FA/MFA needs to be enabled.
03-13-2022 07:20 AM
Take a look at the following to see if this could be an option to meet your end goals: https://www.pragmasys.com/products/support/cisco-2-factor
NOTE: for the devices or tools that do not require 2FA you can enable both (x509 + password) via: ip ssh server algorithm authentication publickey password
HTH!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide