Nebula USG Flex Remote Access VPN and Two-Factor Authentication
Remote clients can VPN using the latest version of SecuExtender IPSec client, but I don't know how to access / force them to access the Captive Portal to allow local network access. How do I force the client to go to the captive portal, or what is the portal IP Address (I tried the first and last usable IP of the VPN Subnet without a response)?
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
0
Accepted Solution
All Replies
-
-
Thank you, Jonas - Step 6 is what I was missing. This works as expected now.1
Categories
- All Categories
- 415 Beta Program
- 2.3K Nebula
- 142 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 230 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 39 Wireless Ideas
- 6.3K Consumer Product
- 246 Service & License
- 385 News and Release
- 82 Security Advisories
- 28 Education Center
- 9 [Campaign] Zyxel Network Detective
- 3.1K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight