cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
76159
Views
22
Helpful
23
Replies

Two-factor Authentication Recommendations for ASA 5510 VPN

smiths@prpa.org
Level 1
Level 1

Hello,

I'm wondering what people are using and/or recommending for two-factor authentication for VPN users on the Cisco ASA platform?

Steve

23 Replies 23

Have you checked out Duo Security's native Cisco two factor authentication service? No hardware or software required and it installs in minutes. Users can then enroll in-line. Check it our... www.duosecurity.com/docs/cisco

gbrowinski
Level 1
Level 1

PortalGuard's PassiveKey®, a secure one time password, is a great solution. It protects against network attacks with a secure server login without negatively impacting the end user. No hardware necessary Check it out here http://www.portalguard.com/vpn-authentication.html. PortalGuard also supports YubiKey and RSA.

http://www.portalguard.com

 

 

Michael Muenz
Level 5
Level 5

Safenet Authentication Manager Express with eToken PASS 3000. 

You can use the NPS/Radius from Windows itself, or install ESP to use the internal Radiusservice.

Works great and you can install the one lincense on multiple Domain Controllers and replicate the setup

Michael Please rate all helpful posts

techtonic72
Level 1
Level 1

Check out this blog on "How to connect your smartphone or tablet to a Cisco VPN using two factor authentication": 

https://www.logintc.com/blog/2015-01-28-connect-cisco-vpn-on-mobile-with-two-factor.html 

Or this page has non-mobile instructions: https://www.logintc.com/docs/connectors/cisco-asa.html

fdhuart-nextira
Level 1
Level 1

OpenOTP from RCDevs, It rocks !!!

 

Many Very cool features like Auth failback to other Mechanims (ex: soft-tokens In case you forgot your Hardware one), SSO, different Backend Supported AD,OpenLDAP, 389 DS, SQL, etc ... ). OpenOTP also support yubikey.

 

They received an OATH-HOTP Certification.

50 User Licenses for Free :-)

 

Proactive Development and Support.

 

can you elaborate?  is the OpenOTP solution workable with the Cisco IPSec client?

i've trialled the DUO solution and it works great, but for $36 per user per year it's kind of expensive for smaller firms like our (less than 100 employees, and less than 40 with VPN needs)

s.flanigan
Level 1
Level 1

Check out these guys: www.logintc.com

They have a RADIUS appliance for Cisco ASA: https://www.logintc.com/docs/connectors/cisco-asa.html

Pretty responsive for support.

Stan

vsurresh
Level 1
Level 1

I am currently testing DUO MFA with Cisco AnyConnect VPN, working flawlessly. The set up would take less than 10 minutes. Duo charges $3 per user and you can use the license with any other applications such as O365. 

 

They do provide 30 days trial, give it a try.