One 2FA Google Autheticator in USG for both boot images.

Options
Kv3
Kv3 Posts: 21
First Comment Friend Collector Eighth Anniversary
image  Freshman Member

Hi all,

USG FLEX 500 has two boot images (firmware 1 and 2), each with its own configuration. I use two-factor authentication for admins with the Google Autheticator method. Even if I transfer the configuration from firmware 1 to firmware 2, each uses its own registration in Google Authenticator, so they use different codes. Is there a way to set 2FA to use the same codes for both firmwares?

Accepted Solution

  • Zyxel_Tina
    Zyxel_Tina Posts: 1,010
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 250 Answers 500 Comments
    image  Zyxel Employee
    edited September 15 Answer ✓
    Options

    Hi @Kv3,

    May I first ask which firmware versions you are currently using for each boot image?

    Regarding your requirement to use the same Google Authenticator code for both firmware images, we’ve tested this scenario on our side and confirmed that it is workable. Below are the steps we followed for your reference:

    Note: Please make sure to back up the configurations for both firmware before proceeding.

    1. (On Firmware 1 - V5.39)
      Navigate to CONFIGURATION > Object > User/Group > Local Administrator, edit the "admin" account and enable Two-Factor Authentication and register Google Authenticator.
    2. Go to MAINTENANCE > File Manager > Configuration Files and download the startup-config.
    3. Upgrade the device into Firmware 2 - V5.40.
      (My Firmware 2 haven't done any configuration)
    4. Once on Firmware 2, go to MAINTENANCE > File Manager > Configuration Files and upload the startup-config you exported from Firmware 1.
    5. After the device reboots, you should be able to log in with the same admin credentials and use the same Google Authenticator code.

    If you've followed these steps correctly but the issue still persists, please allow us to investigate further. We may need to remotely access your device to identify any configuration inconsistencies.

    Update: We confirm that this method is no longer applicable. The Google Authenticator secret is not carried over through the startup configuration file. Instead, it is synchronized during the firmware upgrade process, when a firmware image is uploaded to the standby partition and the device reboots using it.

    For the complete, updated procedure, please refer to this newer thread.

    Zyxel Tina

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 1,010
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 250 Answers 500 Comments
    image  Zyxel Employee
    edited September 15 Answer ✓
    Options

    Hi @Kv3,

    May I first ask which firmware versions you are currently using for each boot image?

    Regarding your requirement to use the same Google Authenticator code for both firmware images, we’ve tested this scenario on our side and confirmed that it is workable. Below are the steps we followed for your reference:

    Note: Please make sure to back up the configurations for both firmware before proceeding.

    1. (On Firmware 1 - V5.39)
      Navigate to CONFIGURATION > Object > User/Group > Local Administrator, edit the "admin" account and enable Two-Factor Authentication and register Google Authenticator.
    2. Go to MAINTENANCE > File Manager > Configuration Files and download the startup-config.
    3. Upgrade the device into Firmware 2 - V5.40.
      (My Firmware 2 haven't done any configuration)
    4. Once on Firmware 2, go to MAINTENANCE > File Manager > Configuration Files and upload the startup-config you exported from Firmware 1.
    5. After the device reboots, you should be able to log in with the same admin credentials and use the same Google Authenticator code.

    If you've followed these steps correctly but the issue still persists, please allow us to investigate further. We may need to remotely access your device to identify any configuration inconsistencies.

    Update: We confirm that this method is no longer applicable. The Google Authenticator secret is not carried over through the startup configuration file. Instead, it is synchronized during the firmware upgrade process, when a firmware image is uploaded to the standby partition and the device reboots using it.

    For the complete, updated procedure, please refer to this newer thread.

    Zyxel Tina