This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Duo Integration with Sophos XG for 2FA

Hello,

I have integrated Cisco Duo with Sophos XG (running firmware 18.01), but have issues with SSL VPN. My AD is my Primary authentication method, while Duo is my second factor authentication. When I test connection, all works well.

I have changed the SSL authentication method to use Duo first, when I try to VPN, I do receive a PUSH which I approve, but still fails (wrong username or something like that). I see it on Duo as successful, but still would not work.

Has anyone done this integration recently on firmware 18 now that we can set timeout values.

Thanks.



This thread was automatically locked due to age.
Parents Reply Children
  • Did this write up ever happen? At the Sophos end, did you setup the DUO Proxy as an LDAP server or an AD server?

    I can get DUO proxy to work as an AD server in Sophos but not as an LDAP server. Unfortunately I want to retain my principal AD server setup and add DUO Proxy as an additional authentication server (using a different port). Sophos won't allow me to have two AD servers on the same IP so I need to run the DUO Proxy as an LDAP server in Sophos and I can't get it to work.

    I'll start a new post with the issue I'm facing but before I did I wondered if this ever got written up so I can have a look first.