Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to configure Sophos IPsec client with 2FA (using Google Authenticator)?

I can establish an IPsec VPN connection but would like to incorporate 2FA (hoping to use Google Authenticator).

This link indicates it's possible: https://blogs.sophos.com/2014/02/21/whats-coming-in-sophos-utm-accelerated-9-2-4-safer-two-factor-authentication/

Please advise.

Thank you!

-Roque



This thread was automatically locked due to age.
Parents Reply
  • Thank you for your assistance.

    I feel like I may not be giving you all the details:

    1.) UTM was initially setup with OTP using the Sophos SSL VPN Client (also with active directory authentication).  SSL VPN remote access with OTP is active and operational.

    2.) Next, the Sophos IPsec Client was setup without OTP.  Profile and certificate were downloaded from the UTM.  After entering the PIN, the IPsec Client is fully operational.

    3.) Now, OTP is implemented per the instructions you provided, BUT OTP is not working. After the PIN is entered, the connection is established.  I do not get prompted for the Google Autehnticator passcode.

     

    Should I remove the IPsec client and start from scratch?

    Thanks again!

Children
  • Did you put a checkmark to enable OTP on IPSec remote access as was explained in earlier posts:

    While setting up one time passwords, you MUST check off which service (facility) you want to use with the one time password with.  One of the services is "IPsec Remote Access".

     

    If this has been checked, you shouldn't get access without the 6 digit-code added to the usual password.