Authenticate remote access VPN users using secondary authentication
Configure secondary authentication in addition to primary authentication to provide additional security for VPN sessions.
Secondary authentication applies only to AAA-only and Client Certificate & AAA authentication methods. Users gain access if both primary and secondary authentications succeed. If either authentication fails or a server is unreachable, users are denied access.
Secondary authentication requires VPN users to enter two sets of credentials in Secure Client. You can also configure the system to pre-fill the secondary username from the authentication server or client certificate.
Before you begin
Configure a AAA server to serve as the secondary authentication server.
For example, you can set the primary authentication server as an LDAP or Active Directory realm and the secondary authentication as a RADIUS server.
Follow these steps to authenticate remote access VPN users using secondary authentication:
Procedure
Step 1 | Choose |
Step 2 | Click the edit icon next to the remote access VPN policy. |
Step 3 | Click the edit icon next to the connection profile that you want to modify and click the AAA tab. |
Step 4 | From the Authentication Method drop-down list, choose AAA-only or Client Certificate & AAA. |
Step 5 | From the Authentication Server drop-down list, choose the primary AAA server. |
Step 6 | (Optional) Check the Fallback to LOCAL Authentication check box to enable user authentication using the LOCAL database if the AAA server group is unavailable. Ensure that the LOCAL database is configured. |
Step 7 | Check the Use secondary authentication check box to configure a secondary AAA server and from the Authentication Server drop-down list, choose the secondary AAA server.. |
Step 8 | In Username for secondary authentication, configure these parameters:
|
Step 9 | Click Save to save the remote access VPN policy. |