2FA authentification email not receiving
Hi all
I have successfully activated 2FA with a ZyWall 110. Emails with authentication link will be sent to the VPN users. But the emails will not be received. Issue there I see is, that with the setup (tunneling all traffic), the client cannot resolve (DNS) the FQDN and cannot connect to the email server, as all traffic is declined, as long the authentication is not executed. If I execute for testing purpose the authentication with another client who can receive the email, it works like a charm.
If I send the authentication link by SMS, it will work with the WAN IP address to http (80). But when I send the authentication link with the FQDN of the entry point (http and https), it will not work. I see same issue: DNS cannot be resolved based on traffic declined.
Target would be: authenticate by email, send link with https (SSL) for safety reason.
Is there any possibility or any workarounds, to let the client receive an email trough the VPN, as long the authentication is not executed? For example with a special security rule who is just in use for authentication (like permit traffic from VPN authentication to WAN).
Accepted Solution
-
Hi @Dany
Before client click “Authorize” button in 2FA authentication mail, client’s traffic unable pass to internet or internal subnet.
In the usual, this kind of scenario needs 2 networking devices. One is for establishing VPN tunnel, other one is for receiving/authorizing the authentication mail.
According FQDN setting, you have to setup DDNS on WAN interface and allow HTTP/HTTPS traffic from WAN to ZyWALL.
5
All Replies
-
Hi @Dany
Before client click “Authorize” button in 2FA authentication mail, client’s traffic unable pass to internet or internal subnet.
In the usual, this kind of scenario needs 2 networking devices. One is for establishing VPN tunnel, other one is for receiving/authorizing the authentication mail.
According FQDN setting, you have to setup DDNS on WAN interface and allow HTTP/HTTPS traffic from WAN to ZyWALL.
5 -
Hi @Zyxel_Stanley
Thank You for Your answer. So, it is as I expected not designed/possible to establish and authenticate the VPN tunnel with the same (one) device over email in combination with the FQDN.
It only works with one device over the WAN IP address and http (not https, as there would be a certification proving error as WAN IP address ≠ FQDN) and SMS, as the SMS can be received by the one device (using the cell network).
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight