Set up MFA / 2FA for IKEv2 on Flex 200h

2»

All Replies

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @PeterUK

    First, please ensure your configuration for 2FA VPN access is set up correctly. You can refer to the guidance article below to verify your setup:

    [USG FLEX H] How to Set Up 2FA with Google Authenticator for Remote Access VPN and SSL VPN

    If you’ve confirmed that the configuration is correct and the issue persists, kindly provide the following details via private message:

    1. HTTPS WAN remote GUI access information.
    2. The type of remote VPN you are using.
    3. A test VPN client account with credentials for us to investigate further.

    Kay

  • Zyxel_Kay
    Zyxel_Kay Posts: 1,279  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - WLAN Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security

    Hi @PeterUK

    After reviewing your case and the device design, we have confirmed that the VPN 2FA page link can only be accessed once the VPN connection is established.

    Regarding the ability to access the VPN 2FA page directly through the WAN IP or LAN IP on port 8008 after disabling the firewall rule, this behavior is consistent with the default design of the current firewall web server and is considered normal.

    Kay

  • PeterUK
    PeterUK Posts: 3,535  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Well openVPN was installed in the lower right sys tray for you to try even when VPN was connected you can't get to the 2FA page

  • PeterUK
    PeterUK Posts: 3,535  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited January 17

    So...I worked out my mistake because VirtualBox had IP 192.168.255.43 and 2FA as 192.168.255.39 it didn't go down the VPN testing with another IP subnet to the firewall worked.

    stil would like the following

    2FA authentication by EMail — Zyxel Community