Configure RSA two-factor authentication

You can configure your RADIUS or AD server as the authentication agent in the RSA server. Use it as the primary authentication source for your remote access VPN policy. Users authenticate with a username that exists in the RADIUS or AD server. In the password field, users must concatenate their password and the one-time RSA token, separated by a comma, in this format: password,token.

In this setup, it is common practice to use a dedicated RADIUS server, such as Cisco ISE, for authorization. You can configure this second RADIUS server as the accounting server too.

Before you begin

Ensure that you review Prerequisites for configuring RSA two-factor authentication.

Procedure


Step 1

In Cloud-Delivered Firewall Management Center, choose Objects > AAA Server > RADIUS Server Group to configure a RADIUS server object.

Step 2

Configure the RADIUS server in the RADIUS server object with a timeout of 60 seconds or more.

Step 3

Configure a new remote access VPN policy or edit an existing policy.

Step 4

In Authentication, Authorization & Accounting (AAA), from the Authentication Method drop-down list, choose AAA and add the RADIUS server as the authentication server.

Step 5

Deploy the configuration on the device.