Authenticate remote access VPN users using secondary authentication

Configure secondary authentication in addition to primary authentication to provide additional security for VPN sessions.

Secondary authentication applies only to AAA-only and Client Certificate & AAA authentication methods. Users gain access if both primary and secondary authentications succeed. If either authentication fails or a server is unreachable, users are denied access.

Secondary authentication requires VPN users to enter two sets of credentials in Secure Client. You can also configure the system to pre-fill the secondary username from the authentication server or client certificate.

Before you begin

Configure a AAA server to serve as the secondary authentication server.

For example, you can set the primary authentication server as an LDAP or Active Directory realm and the secondary authentication as a RADIUS server.

Follow these steps to authenticate remote access VPN users using secondary authentication:

Procedure


Step 1

Choose Secure Connections > Remote Access VPN

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the edit icon next to the connection profile that you want to modify and click the AAA tab.

Step 4

From the Authentication Method drop-down list, choose AAA-only or Client Certificate & AAA.

Step 5

From the Authentication Server drop-down list, choose the primary AAA server.

Step 6

(Optional) Check the Fallback to LOCAL Authentication check box to enable user authentication using the LOCAL database if the AAA server group is unavailable.

Ensure that the LOCAL database is configured.

Step 7

Check the Use secondary authentication check box to configure a secondary AAA server and from the Authentication Server drop-down list, choose the secondary AAA server..

Step 8

In Username for secondary authentication, configure these parameters:

  • Prompt—Prompts users to enter their username and password when logging in to the VPN gateway.
  • Use primary authentication username—Uses the username of the primary authentication server for both primary and secondary authentication. Users must enter two passwords when they log in.
  • Prefill username from certificate on user login window—Pre-fills the secondary username from the client certificate when the user connects through Secure Client.
    • Select Map specific field to use certificate fields as the username, with the default Primary and Secondary fields set to CN (Common Name) and OU (Organizational Unit).

    • From the Primary and Secondary drop-down lists, choose the required certificate fields.

    • Select Use entire DN (Distinguished Name) as username to automatically retrieve the user identity from the DN. This unique identifier is used to match users to a connection profile and supports enhanced certificate authentication.

    • If you have enabled the Enable multiple certificate authentication option, from the Certificate to choose drop-down list, choose First Certificate or Second Certificate.

    • Hide username in login window—Pre-fills the secondary username from the client certificate. This username is hidden from the user, preventing modification of the pre-filled username.

    • Use secondary username for VPN session—Uses the secondary username for reporting user activity during a VPN session.

Step 9

Click Save to save the remote access VPN policy.