cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
818
Views
0
Helpful
1
Replies

Configuring ASA to use Authanvil two factor authorization - Radius

bberry
Level 1
Level 1

I am trying to setup a Proof Of Concept using Scorpion's AuthAnvil two factor. This appears to work as a radius server but I have never set one up on the ASA platform. I am looking to see if someone can point me in the direction of a configuration guide or provide some basic assistance on setting up a Radius server in a AAA server group. I have gone through what I think is the correct steps but testing fails and I do not know if that is expected or if I missed something in the config. I did it without any documentation so may have things completely wrong and figure to start over from scratch and do it proper. 

I am also wondering if anyone else has used or tried to use AuthAnvil with the ASA. I search of that on CCO has turned up nothing. Do not know if this is a good or bad thing but figured would ask before I get too far down the road. I have also looked at the DUO product but management want a look at this as well. Any comments or guidance is welcome.

Brent

1 Reply 1

Rahul Govindan
VIP Alumni
VIP Alumni

Configuring a Radius server on the ASA can be done be similar to this:

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/117641-config-asa-00.html

I have not used AuthAnvil two factor authentication personally, but have implemented Duo passcode with Cisco ASA. This has worked very well so far. There are a few ways to go about this (Radius proxy or LDAPs), and the easiest method I have seen is to use Duo with LDAPs. An example of this is here:

https://duo.com/docs/cisco