Prerequisites for configuring Duo two-factor authentication

Review these prerequisites before configuring Duo two-factor authentication for remote users in Secure Firewall.

  • Configure a primary authentication RADIUS or AD server for your remote access VPN users.

  • Create a Duo administrator account in Duo Admin Panel.

  • Enroll users in Duo using the Duo Admin Panel.

  • Create a Duo-protected application to integrate Duo with your Firewall Threat Defense device.

    This application generates an integration key, a secret key, and an API hostname. You need these parameters when you configure the authproxy.cfg file using Duo Authentication Proxy.

  • Install Duo Authentication Proxy on a Windows or Linux machine in your network. The Duo proxy server also works as a RADIUS server.

    Download and install the most recent Duo Authentication Proxy.

    To verify the checksum, refer to the Duo documentation at https://duo.com/docs/checksums#duo-authentication-proxy.

  • Configure authproxy.cfg, the Duo authentication file.

    The authproxy.cfg file contains details of the RADIUS or ISE server, the Firewall Threat Defense device, the Duo proxy server details, the integration key, the secret key, and the API host details. For more information, refer to https://duo.com/docs/cisco-firepower#configure-the-proxy.