Prerequisites for configuring RSA two-factor authentication

Review these prerequisites for configuring RSA two-factor authentication in Secure Firewall, covering requirements for both RSA server and ISE server configurations.

Prerequisites for RSA server

  • Configure RADIUS or AD server as an authentication agent. Add this server as the authentication server for the remote access VPN policy in Cloud-Delivered Firewall Management Center.

  • Generate and download the configuration file (sdconf.rec).

  • Create a token profile and assign the token to the user.

  • Give the token to the user after assigning it.

  • Download and install the token in the remote access VPN client.

For more information, refer to RSA documentation.

Prerequisites for ISE server

  • Import the configuration file (sdconf.rec) from the RSA server.

  • Add the RSA server as the external identity source.

  • Configure the shared secret.