MFA with AD authentication?
I am using a USG Flex500. Users login to SSL VPN with their AD credentials (setup via Auth. Method/AAA Server in object). However if I try to setup MFA for this users group, I don't get the "set up google authenticator screen" option. It seems this setup is only shown for local users. You can try this yourselves with the "ad-users" built-in groups.
How do I setup MFA for AD authenticated users?
How do I setup MFA for AD authenticated users?
0
Accepted Solution
-
Hi @howtired,
Please refer the following KB.
How to set up two factor authentication for admin login by Email to SMS
And please fill in the following mobile number in AD server.
Thank you
Kevin
0
All Replies
-
Sorry: ATP500, not Flex.0
-
Hi @howtired,
Greeting Forum, MFA only support local user.
For ext-user or ext-group-user, to implement MFA, please kindly use SMS/Email to replace.
Thank you
Kevin0 -
hi Kevin,
Thanks for your answer.
How would I setup MFA via SMS? I can tick the option but there's no instructions on how to add a phone number and which SMS service provider to use. Is there something on Zyxel KB documenting this?0 -
Hi @howtired,
Please refer the following KB.
How to set up two factor authentication for admin login by Email to SMS
And please fill in the following mobile number in AD server.
Thank you
Kevin
0 -
Zyxel_Kevin said:Hi @howtired,
Please refer the following KB.
How to set up two factor authentication for admin login by Email to SMS
And please fill in the following mobile number in AD server.
Thank you
Kevin
This is working for AD users, although in a different way than described in the kb you linked.
The SMS sent to the user does not contain a verification code, but instead a link to the public IP of the ATP500 (on the port configured for MFA). Here they need to click on the "activate" button to gain VPN access. Not a solution I like, since it forces me to open yet another port on the ATP, plus we don't have a public certificate so the user gets all the usual security warnings when clicking on the link.
Anyway, thanks a lot for your help.0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight