cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
566
Views
0
Helpful
9
Replies

2FA on Anyconnect Remote VPN

fmugambi
Spotlight
Spotlight

Hello Team,

Need ideas on how to implement 2FA on cisco AnyConnect for remote VPN.

Currently users are authenticating via Microsoft AD.

Thank you.

9 Replies 9

sadks
Cisco Employee
Cisco Employee

Hi,

What is the other authentication method you are planning to use?

 

 

using Google Authenticator so users would have to download an app on their phone which generates an OTP for them to use

Hi,

You can refer to this for configuring the aaa-server :

https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/213931-configure-anyconnect-secure-mobility-cli.html#toc-hId-1996450613

Just have to make sure that the other aaa-server must be configured as secondary authentication.

for example:

tunnel-group <name> general-attributes
authentication-server-group <Microsoft AD server>
secondary-authentication-server-group <second factor>

 

 

 

 

where do i get the option for "secondary-authentication-server-group <second factor>" ?

Hi,

What is your VPN headend?

 

cisco firepower.

Hi,

if you are using FMC then you will have a checkbox under connection profile to use secondary authentication.

for example:

 

sadks_5-1706615005374.png

 

sadks
Cisco Employee
Cisco Employee

Hi,

did that help? or do you have any more queries?

 

trying to figure out how to add a 3rd party aaa > to use as secondary authentication.