Configure two-factor authentication

Firewall Threat Defense devices support two-factor authentication that requires users to verify their identity through two separate steps before gaining access. With two-factor authentication enabled, a user must provide a username and static password, and an additional verification item, such as an RSA token or a passcode. Both factors are handled by a single authentication source. The two-factor authentication server connects directly to the primary authentication source. Two-factor authentication adds an extra layer of identity verification to your remote access VPN.

Firewall Threat Defense devices support these two factors for two-factor authentication:

  • RSA tokens—A time-based one-time passcode generated by an RSA device or application.

  • Duo Push—An authentication request pushed to the Duo Mobile application for user approval.