Nebula USG Flex Remote Access VPN and Two-Factor Authentication
Remote clients can VPN using the latest version of SecuExtender IPSec client, but I don't know how to access / force them to access the Captive Portal to allow local network access. How do I force the client to go to the captive portal, or what is the portal IP Address (I tried the first and last usable IP of the VPN Subnet without a response)?
I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:




I have configured the remote access VPN and can connect to the USG FLEX successfully. When I do not have the "Two-factor authentication" option selected, my remote client can access network resources. I am using the SecuExtender IPSec client version 5.6.80.007.
When I enable the "Two-factor authentication" option, the remote client cannot access local network resources (as expected - the second factor is pending). I can browse external sites while connected to the VPN.
I've configured LAN 1, our internal network, to allow direct client access without authentication (USG Flex -> Configure -> Authentication Method). I've set up a static route (USG Flex -> Configure -> Routing) to connect the Remote Access subnet to our LAN 1 subnet.
My Cloud Authentication (Organization-wide -> Configure -> Cloud authentication) user that I authenticate with has two-factor authentication enabled and the option to bypass two-factor authentication is not checked.
Remote Access VPN Configuration Settings:

0
Accepted Solution
All Replies
-
Thank you, Jonas - Step 6 is what I was missing. This works as expected now.1
Categories
- All Categories
- 164 Beta Program
- 1.7K Nebula
- 86 Nebula Ideas
- 62 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 50 Switch Ideas
- 907 WirelessLAN
- 27 WLAN Ideas
- 5.3K Consumer Product
- 172 Service & License
- 294 News and Release
- 65 Security Advisories
- 14 Education Center
- 911 FAQ
- 399 Nebula FAQ
- 249 Security FAQ
- 90 Switch FAQ
- 100 WirelessLAN FAQ
- 18 Consumer Product FAQ
- 55 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 68 About Community
- 51 Security Highlight
Zyxel Employee