Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RADIUS for UTM Webadmin?

Currently using RADIUS to authenticate users for VPN (L2TP). Works fine.

I have been instructed to add 2FA to the UTM for both VPN and for WebAdmin. We use Duo for 2FA.

I set up a Duo proxy server as described in multiple documents and tied it to the UTM using RADIUS. The problem: how do I specify which users can get to WebAdmin or not? As it stands right now, the UTM sees all RADIUS users the same, so anyone with RADIUS access would be able to get to WebAdmin. Clearly I don't want every single user to have access to WebAdmin.



This thread was automatically locked due to age.
Parents
  • Hi LeeSentell,

    for users who need access to webadmin, the users have to be entities on the UTM, this way the user have an account on the UTm already, rather than authenticating with an external source (which effectively what RADIUS is).

    XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)
    Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!

  • Okay, then how to provide 2FA for WebAdmin logins? Duo's proxy server provides RADIUS and the UTM is supposed to obtain authentication in that way from the proxy server, according to Sophos docs.

    We have both admins and users configured with Duo. How to ensure that only admins can get access to WebAdmin and not users?

Reply
  • Okay, then how to provide 2FA for WebAdmin logins? Duo's proxy server provides RADIUS and the UTM is supposed to obtain authentication in that way from the proxy server, according to Sophos docs.

    We have both admins and users configured with Duo. How to ensure that only admins can get access to WebAdmin and not users?

Children
No Data