We want to enable Certificate only Authentication with smart card. FTD takes username from cert forwards it to ISE(RADIUS), ISE forwards it to DUO-proxy. DUO should check that username in AD, and after that user should receive DUO PUSH on the pho...
Finally the solution of our case is:
We enabled [duo_only_client] on the DUO-Proxy, which is already exist like [ad_client].
Config looks like:
Thank you for the reply.
Your solution seems good, but there is another question:
We have configured Duo-proxy like ad_client, so that proxy makes 1FA and 2FA. Can we configure proxy like ad_client and duo_only_client simultaneously and split ...