I didn't realize that Cisco ASAs will only send login credentials via PAP to Windows Radius Servers for admin users? From what I can find, MS-CHAP v2 is only supported for tunnel/VPN users? I was hoping to use Cisco Duo to implement MFA for a variety...