Nebula USG Flex Remote Access VPN and Two-Factor Authentication
Options
Remote clients can VPN using the latest version of SecuExtender IPSec client, but I don't know how to access / force them to access the Captive Portal to allow local network access. How do I force the client to go to the captive portal, or what is the portal IP Address (I tried the first and last usable IP of the VPN Subnet without a response)?
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:




I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:

0
Accepted Solution
All Replies
-
-
Thank you, Jonas - Step 6 is what I was missing. This works as expected now.1
Categories
- All Categories
- 434 Beta Program
- 2.7K Nebula
- 174 Nebula Ideas
- 117 Nebula Status and Incidents
- 6.1K Security
- 418 USG FLEX H Series
- 297 Security Ideas
- 1.6K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 43 Wireless Ideas
- 6.7K Consumer Product
- 269 Service & License
- 416 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 87 Security Highlight