12-15-2024 05:59 AM
I’m working on securing RA-VPN (Anyconnect) on Cisco Firepower Device Manager (FDM), Not FMC and would like to understand its compatibility with Multi-Factor Authentication (MFA) solutions.
Your expertise and recommendations would be greatly appreciated.
Feel free to share your thoughts in the comments or message me directly. 
#Anyconnect #CiscoFDM #MFA #NetworkSecurity
Solved! Go to Solution.
12-15-2024 07:14 AM - edited 12-15-2024 07:18 AM
@GHOZLANE Haroun the Azure MFA link provided is for FDM - "Configure RAVPN with SAML Authentication Using Azure as IdP on FTD Managed by FDM" The other link is the FDM admin guide.
Your screenshot is referencing features introduced in 6.4, the current version 7.6. Since 6.4 SAML authentication has been introduced.
FDM supports SAML for RAVPN authentication, so if the other MFA solutions used SAML then I would expect it to work. Or if the solution i.e. FortiAuthenticator supports RADIUS authentication then you can also set the FDM authentication to use RADIUS for MFA.
12-15-2024 06:13 AM - edited 12-15-2024 06:55 AM
Cisco has a guide to integrate FDM with Cisco Duo, which would be Cisco's recommended MFA solution - https://duo.com/docs/cisco-firepower
Do you mean Azure MFA? Cisco also has an integration guide https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221659-configure-ravpn-with-saml-authentication.html
You can also easily integrate FDM RAVPN with any RADIUS server, including ISE - https://www.cisco.com/c/en/us/td/docs/security/firepower/740/fdm/fptd-fdm-config-guide-740/fptd-fdm-ravpn.html
When you do integrate MFA with FDM the default timeout is too low to allow the user enough time to enter the second factor authentication, so you should increase the timeout to 60 seconds (Cisco recommended).
Ideally using FMC (on premise or cloud with cdFMC) would be recommended, as using FDM supports less features.
12-15-2024 07:06 AM
Hi Rob,
thanks for your answers .
the link you shared is for FMC not FDM ,
as per the link bellow  the FDM support only DUO and RSA   for MFA , what about FortiAuthenticator and other MFA ?
Regards
12-15-2024 07:14 AM - edited 12-15-2024 07:18 AM
@GHOZLANE Haroun the Azure MFA link provided is for FDM - "Configure RAVPN with SAML Authentication Using Azure as IdP on FTD Managed by FDM" The other link is the FDM admin guide.
Your screenshot is referencing features introduced in 6.4, the current version 7.6. Since 6.4 SAML authentication has been introduced.
FDM supports SAML for RAVPN authentication, so if the other MFA solutions used SAML then I would expect it to work. Or if the solution i.e. FortiAuthenticator supports RADIUS authentication then you can also set the FDM authentication to use RADIUS for MFA.
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide