Configure Device for Duo RADIUS Using Security Cloud Control

Procedure


Step 1

Configure FTD Radius Server Object.

  1. In the left pane, click Objects.

  2. Click > RA VPN Objects (ASA & FTD) > Identity Source.

  3. Provide a name and set the Device Type as FTD.

  4. Select Radius Server Group and click Continue. For details, see step 6 in Create a RADIUS Server Group.

  5. In the Radius Server section, click the Add button and click Create New Radius Server. See Create a RADIUS Server Object

    In the Server Name or IP Address field, enter your Duo Authentication Proxy server's fully-qualified hostname or IP address.

  6. Once you have added the Duo RADIUS server to the group, click Add to create the new Duo RADIUS server group.

Step 2

Change the Remote Access VPN Authentication Method to Duo RADIUS.

  1. In the left pane, click Secure Connections > Remote Access VPN > ASA & FDM.

  2. Expand the VPN configuration and click on the connection profile to which you want to add Duo.

  3. In the Actions pane on the right, click Edit.

  4. Select the Authentication Type can be AAA or AAA and Client Certificate.

  5. In the Primary Identity Source for User Authentication list, select the server group you created earlier.

  6. You typically do not need to select an "Authorization Server" or "Accounting Server".

  7. Click Continue.

  8. In the Summary and Instructions step, click Done to save the configuration.

Step 3

Review and deploy now the changes you made, or wait and deploy multiple changes at once.