Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

2FA-Token (OTP) for IPSec-RemoteAccess without SophosConnect Client

Hello,

we have the following problem. 

We need to ensure remote access for an external support company. For those 24/7 remote access we need mandatory any type of two factor authentication in IPSec.

For internal home-office remoteaccess clients we use sophos connect client.

The external company cant install sophos connect client, because of high investments in IT administration.

So my question: Is it possible to use the Sophos RemoteAccess VPN (or legacy ipsec remoteaccess) with an user based otp token? For example add in X-Auth the OTP after the normal user password? Anyone tested these with NCP Secure Entry Client?

thanks!



This thread was automatically locked due to age.
Parents
  • I would highly recommend to overthink this principle of giving somebody VPN access, which is not part of your company. One of many security issues to begin with.

    But in theory, this works. You can use other IPsec /SSLVPN clients with the firewall, as the protocols are standard. 

  • I know - but for the moment it is mandatory. We have many other security things active to secure these access (manual enabling of vpn from an administrator, policys rules only for specific destination clients, internal firewalls, internal authentication and so one).

    OTP with other vpn clients works? You tested it? For me 2FA only works with Sophos Connect Client.

  • You need to add the password + OTP in the password set. 

    So username // password123456 (OTP=123456). This should work with every VPN vendor. Because OpenVPN, Ipsec works the same way in this regards. 

Reply Children