Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN with and without radius/mfa

hello,

we need to use both ssl authentication with radius/mfa for admins and no mfa for normal users.

ssl authentication servers are radius and AD.

when i (admin user) connect to openvpn, i need to use mfa but if i wait without validating mfa, i will be connected because Radius and AD are both in ssl vpn  selected authentication servers.

what can i do to solve my problem?

thank you



This thread was automatically locked due to age.
Parents Reply Children
  • hello, i already used this tutorial to configure mfa with ms radius/Azure AD and SSL sophos vpn.

    let me show you.

    For the vpn firewall rules, i have 2 AD groups (radius with mfa and AD without mfa). My account is in the MFA group and not in AD Group.

    When i log in the vpn client, sophos firewall tries to validate 1st in local, then radius, get no answer (timeout) from the radius because i don't validate the mfa then tries AD servers, and validate the authentication.

    i need both Radius and AD Authentication servers, admins with mfa and users without.

    the situation is little bit different from the tutorial.

    thanks.