Nebula USG Flex Remote Access VPN and Two-Factor Authentication
Options
Remote clients can VPN using the latest version of SecuExtender IPSec client, but I don't know how to access / force them to access the Captive Portal to allow local network access. How do I force the client to go to the captive portal, or what is the portal IP Address (I tried the first and last usable IP of the VPN Subnet without a response)?
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:
0
Accepted Solution
All Replies
-
-
Thank you, Jonas - Step 6 is what I was missing. This works as expected now.1
Categories
- All Categories
- 397 Beta Program
- 2.1K Nebula
- 116 Nebula Ideas
- 78 Nebula Status and Incidents
- 5.1K Security
- 52 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 70 Switch Ideas
- 907 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 211 Service & License
- 332 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 1.9K FAQ
- 880 Nebula FAQ
- 415 Security FAQ
- 221 Switch FAQ
- 195 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 137 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 63 Security Highlight