Nebula USG Flex Remote Access VPN and Two-Factor Authentication
Remote clients can VPN using the latest version of SecuExtender IPSec client, but I don't know how to access / force them to access the Captive Portal to allow local network access. How do I force the client to go to the captive portal, or what is the portal IP Address (I tried the first and last usable IP of the VPN Subnet without a response)?
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
0
Accepted Solution
All Replies
-
-
Thank you, Jonas - Step 6 is what I was missing. This works as expected now.1
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight