Configure RSA two-factor authentication
You can configure your RADIUS or AD server as the authentication agent in the RSA server. Use it as the primary authentication source for your remote access VPN policy. Users authenticate with a username that exists in the RADIUS or AD server. In the password field, users must concatenate their password and the one-time RSA token, separated by a comma, in this format: password,token.
In this setup, it is common practice to use a dedicated RADIUS server, such as Cisco ISE, for authorization. You can configure this second RADIUS server as the accounting server too.
Before you begin
Ensure that you review Prerequisites for configuring RSA two-factor authentication.
Procedure
Step 1 | In Cloud-Delivered Firewall Management Center, choose to configure a RADIUS server object. |
Step 2 | Configure the RADIUS server in the RADIUS server object with a timeout of 60 seconds or more. |
Step 3 | Configure a new remote access VPN policy or edit an existing policy. |
Step 4 | In Authentication, Authorization & Accounting (AAA), from the Authentication Method drop-down list, choose AAA and add the RADIUS server as the authentication server. For more information, see Configure AAA settings for a remote access VPN policy. |
Step 5 | Deploy the configuration on the device. |