This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Duo Integration with Sophos XG for 2FA

Hello,

I have integrated Cisco Duo with Sophos XG (running firmware 18.01), but have issues with SSL VPN. My AD is my Primary authentication method, while Duo is my second factor authentication. When I test connection, all works well.

I have changed the SSL authentication method to use Duo first, when I try to VPN, I do receive a PUSH which I approve, but still fails (wrong username or something like that). I see it on Duo as successful, but still would not work.

Has anyone done this integration recently on firmware 18 now that we can set timeout values.

Thanks.



This thread was automatically locked due to age.
Parents
  • Hello Tobi,

    Thank you for contacting the Sophos Community!

    IF you put an incorrect password on purpose and check the /log/access_server.log, what is the error?

    Also try enabling debugging for the access server log, to turn it off run the same command.

    # service access_server:debug -ds nosync

    If you test the user accessing the User Portal does it work?

    Can you confirm the user that is using DUO has a group assigned to it, as new accounts might be created by the Radius auth, if this is the case add the user to the SSL VPN group and have the user to re-download the config and try again.

    Regards,

  • You need to specify DUO (Radius) for the User Portal as a Authentication service. 

    Then login via User portal (with DUO) and download the new SSLVPN Config. This config should work with DUO. 

Reply Children
  • When I put Duo as the first authentication method in the user portal, I can do 2FA successfully to access the portal, but I can no longer see the SSL VPN tab in order to download the config. I see that tab only when I remove Duo from the authentication method.

    I do not understand this behaviour.