Configure two-factor authentication for remote access VPN users using Duo

Use Duo Multi-Factor Authentication (MFA) to add a second layer of security and protect your organization by verifying user identities. Remote users must authenticate using their credentials and then use a Duo passcode method such as push, phone call, passcode, or SMS.

Before you begin

Ensure that you review Prerequisites for configuring Duo two-factor authentication.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Objects > AAA Server > RADIUS Server Group to configure a RADIUS server object for Duo.

Add the Duo Authentication Proxy as the RADIUS server in the RADIUS server object, and set the timeout to more than 60 seconds. For more information, see RADIUS server group configuration options.

Step 2

Assign the RADIUS server as the authentication server for your remote access VPN policy.

Step 3

Deploy the configuration on the device.


For detailed information about deploying Duo multi-factor authentication for remote access VPN, refer to Configure Duo Multi-Factor Authentication for Remote Workers using Cisco Secure Firewall Management Center.