YouTube transcripts

Firepower Remote Access VPN with Duo for MFA: video thumbnail

Firepower Remote Access VPN with Duo for MFA transcript

Network Wizkid · @NetworkWizkid

Published February 28, 202328:134.6K views

Watch this video on YouTube

Transcript analysisComputed from the caption text

Words

4,067

Runtime

28:13

Speaking pace

144wpm

Reading time

17min

144 words per minute, below the 160 25th percentile of 349 measured videos. That distribution comes from the 349-video hook study.

Opening (first 30 seconds)

[Music] foreign authentication when using the Cisco Firepower or FTD as a VPN termination point so end users are going to connect to the FTD for a more Access VPN capabilities using the secure client The Cisco secure client or Cisco anyconnect and when they enter their username and password being their primary credentials before they are able to access or successfully connect to the VPN they will need to complete jewels

72 words, the words spoken in the first 30 seconds at 144 words per minute.

Sentence shape

MeasureThis transcript
Sentences2
Average words per sentence2033.5
Longest sentence3,559 words
Questions asked0
Sentences containing a number1

Most used terms

  • vpn38
  • um33
  • authentication30
  • configuration19
  • change17
  • connect16
  • uh16
  • authentication proxy15
  • proxy15
  • specify15
  • access14
  • client14

Filler phrases

68 in total: um 33 · uh 16 · actually 11 · you know 3 · basically 2 · I mean 1 · like 1 · sort of 1.

A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.

What this transcript is

Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.

Transcript

[Music] foreign authentication when using the Cisco Firepower or FTD as a VPN termination point so end users are going to connect to the FTD for a more Access VPN capabilities using the secure client The Cisco secure client or Cisco anyconnect and when they enter their username and password being their primary credentials before they are able to access or successfully connect to the VPN they will need to complete jewels to factor Authentication so to get started we have a faux pile Management Center which is managing a demo FTD that we have in our test environment and there is no configuration currently set up for the VPN so first of all we're going to do that in this video I do also have another video on my YouTube channel that goes through the Remote Access VPN configuration so if you are looking at how to configure that then you can also take a look at that video one thing I want to make you aware of is that you need to make sure that you have the relevant VPN capabilities and the VPN license assigned in order to do this so to configure VPN what we need to do is we need to go to devices and then we need to go to remote access and as you can see it's a blank canvas so we're just going to go to add here or add a new configuration whichever option you choose and then we need to give this um Remote Access VPN and name so it's going to take us through the more Access VPN policy Wizard and you can see the steps one through two five here so we're just going to give this a name here I'll just set test dual VP test Duo demo and we're going to leave SSL and ipsec enabled here we're going to add our demo device so I've added that into here and I don't think we need the space is a and once we're happy with that let's click next and now we get to the AAA section and configurations so this is where we need to change a few things here so we're going to use AAA um in our settings you do have the option as well with depending on whatever version you're using with uh with Firepower to make use of saml as well we're going to stick with triple o so our authentication in this case is going to be the duo authentication proxy now the Dual authentication proxy is partially configured in this demo so I do have some configuration here and we can take a look at this when we get back to it but first of all what we're going to do is we're going to assign the IP address of the Dual authentication proxy or in your case if you don't have the authentication proxy currently set up this will be the IP address that you will be assigning to the Dual authentication proxy I need to actually specify it here because I don't have it configured so let me configure new radius server group I'm gonna said you are here uh let's set you up Roxy and we need to add it as a radio server or leave the authentication part and the uh account and the accounting part is 1813 we will specify the IP address and that's going to be again this is the IP address of the Dual authentication proxy and we'll specify a key here as well now the key also needs to match on the Dual authentication proxy as well so just bear that in mind and you do have a few other settings if you do want to choose things using uh you know which specific interface should be used for for this um connection I will leave this as it is for now I'm going to click save and we should be good there with those configuration changes so we'll just go ahead and press save there and now you can see our authentication server is the one that we've just configured now you do have the option to fall back to local authentication but in our case we're not going to do this and you can see for authorization server we're also going to leave it as the default selected as well um we'll just specify a few of our dummy things here that we won't necessarily need but we'll apply anywhere so we'll specify an ipv4 pull and thankfully we've already got one so I'm just going to specify that there we'll leave the IPv6 and Group Policy will leave as default as well again if you are using this in your production environment obviously these settings need to be considered a little bit more and things will likely change so do look into making Necessary changes we already have a anyconnect image in this case uploaded onto this device so we're just going to keep that one there and then um now it's asking us on step four to specify the network interface for the incoming VPN access so this is where uh the the the clients will essentially terminate your VPN termination points so the interverse is is likely going to be your outside interface as well so in my case uh given the lab environment I'm in I'm actually going to specify my relevant interface and then I'm also going to specify a self-signed certificate that I've already got on this device again if you're in a production environment or rolling inside in a production environment uh please make use of signed certificate so that you don't run into any certificate sign-in issues as well there is the option as is with the traditional ASA where you get to choose whether you bypass the ACLS for VPN connections we're just going to leave that as it is for now so we'll just press next and then we get to step five where we've got a summary of the configuration so once we're done with that we'll select finish and then now you can see that we've got the connection profile that we've just configured here as well so that's the configuration done on the Firepower Management Center so we need to now go to deploy that to the eftd so we'll go over to deploy and you could also expand this just to make sure that the settings that you are applying um are correct so you can see I've got a few other configuration changes but the main one that we're looking at here is the VPN configuration and once you're happy to deploy that just go ahead and press the apply can add some notes if you want we're just going to say deploy that's now our Firepower configuration change is deployed for the VPN so now we need to turn our attention to the Dual Administration panel and the duo authentication proxy before we can test and with access to Duo what we want to do is we want to head over to Applications and then protect an application and then we just want to search Firepower you can see we've got a few options so we're going to use the first one we're using SSR single sign-on if we were using saml but we're just going to stick with the top one here which is going to make use of radius and if you do want to check out the documentation you can just open the the link that's next to the application and this will give you all information about how we can set up this particular integration as well as some of the bits of information around the authentication proxy as well so I always recommend when doing these sorts of deployments to always check out the documentation as well from Duo so we'll go to protect now and what we're going to do is we're going to need the integration key secret key and API hostname the secret key do not share or write down um I'll give it to anybody this needs to stay a secret so what we want to do is we want to I always ask customers to set up an application policy which is specific to specific to the deployment that where all the integration that we're looking at so I'm just going to say buy a power VPN demo that's the name we're going to give it and we're just going to say that it doesn't support this particular integration will not support inline enrollment so we could leave that as it is we're just going to say that we'll just keep those two on so we're going to enforce MFA and that uses um have to be enrolled within Duo and we'll just create that again if you're looking at deploying this in in production you may want to focus a little bit more around the policies a Duo has to offer for your particular Integrations for us again we're just going to change this to FTD demo or VPN demo we're going to use the username normalization in my case which is simply going to strip any domain name or anything after the username to allow us to log in and we'll leave the rest as it is so we'll just go ahead and save that okay so that's our application configured and created that we want to use to allow two-fact authentication when accessing our ftd's VPN now the next step and the last step is to focus now on the Dual authentication proxy now this is a lightweight application that needs to be installed in your environment which will allow us to communicate um between uh the identity provider likely being your active directory on premise server and allow us to complete that two-factor Authentication so we need as I said a little bit earlier on we need these free so we need the integration key secret key in apis name now if you're unfamiliar with the authentication proxy do check check out my YouTube channel where I do have a video around in installing the authentication proxy and also check out the duo documentation which will give you more information on what it is and how to sale as I said earlier on we already have it configured we're not going to focus on exactly what everything is but just know that we have our active directory um connection from the from this authentication proxy so this is going to allow us to um validate and communicate with the active directory server before we complete two-factor Authentication the areas we need to focus on are going to be down here now this is what we're going to configure as well so again I would recommend you do check out the documentation here because you can see that we have some information around configuring the authentication proxy and exactly what each option is I'm not going to explain each of these options uh today but we are going to configure these steps now so as I said at the start we do need these so first of all we're going to start off with the integration key and I'm just gonna Mark out these fields here I'm just going to paste in these here as well as we go along so our secret key we do need the secret key as I said this is a demo but what you can see here actually is an encrypted password or secret as well so I do recommend you check out the documentation on how to do that as well with this being a demo I'm just going to copy and paste this in and you you know you will be able to see this but as I say in production environments do make sure that you encrypt these and don't share secret keys with anybody we're going to copy the API last name in here as well and one might be out there and that should actually be the same um let's just quickly do these so radius IP if you have more than one IP address then um it is easy enough to add another one you all you have to do is um change the copy this onto a next line and change number one to number two etc etc so our radius IP is going to be the IP address of the FTD enamel care so the Firepower threat defense so I need to put that in there now so is there a one in my case and again we just need to specify um that secret and one thing actually that I need to point out is that if you encrypt the secrets and passwords in the authentication proxy configuration some of the fields are going to change and so you can see here I've got s key protected and now we we've not encrypt this key so it's not going to work but if you're not encrypting it's important not to specify protected or LC configuration won't work um so I'm going to enter the secret key now again I'll just remove the old information here I'm just going to enter the very secure uh Cisco we're going to use failsafe um as well I'll film mode safe and we're going to specify our client for those primary credentials as our active directory client as well and parts you don't really need to specify unless you're using a custom part um something different than the the usual radius Parts as well once we've done that we need to validate the configuration and save it so we'll just quickly validate that and before I um actually go through with testing what we're going to do you can see here um it's throwing out the errors because we've not encrypted this so just before I validate this I'm just going to remove these protected Parts here at least in the radius server configuration because we're not encrypting these in this particular demo so just remove this here and I'll also remove it under the S key and then if we've just validate that you can see there that we have no issues so let's just go ahead and save that always make sure you validate just to make sure you don't have any issues and once you've saved that now we just need to restart the service for those changes to take effect so once that started what we'll do is we'll just um use the same client now I'm connected to to connect to that VPN and we'll see what the behavior is however just before I do that I just want to add back over to the VPN configuration changes that we did because I want to make sure that we don't get disconnected as part of the connectivity connectivity test so I'm just going to head back over to our remote access and there's also one more thing that I want to point out as well which I see many customers run into and um have to end up changing so if we just go across to our Advanced tab now when we have a look at our group policies I'm using default Group Policy so let's just go into that one and if we just go down to split tunnel we're going to Tunnel specific networks and you can see we've got a tunnel a set of IP addresses in there that we're going to Tunnel so this should allow us not to basically get cut off as part of this test if that tunnel um object is is correct I've not checked that but I'm assuming it's correct so I'm going to leave it the other thing as well is if we just go to our object management and just check out our AAA radius configuration and we go to AAA server and ready server groups and the one that we configured if we just go into it and this is again one thing that I see customers um often forget to do and they end up with um what the Thinker issues until they change this essentially what we want to do in our radius servers we want to change the timeout value so you can see here we have a timeout value of 10 and we can add that all the way up to 300 seconds so I'm just going to change that to 60 seconds um and what that's basically going to allow is users to receive the MFA request and have enough time to be able to authenticate before actually receiving another request now if you leave it at 10 seconds the chances are the user is going to be spammed with multiple um MFA requests and essentially get annoyed with that so we'll we'll leave that at 60 seconds and we'll just save that and we will need to just deploy that again so while we're deploying that in the background we can also test to see if our vpn's open to see if we actually get the desired result with the MFA so we'll just imply that and one more thing in your dual Administration panel you do need to make sure users are already enrolled and by enrolled I mean fully enrolled so that you have a username in here they have a device enrolled and they're good to go so we can see here that um my user Kelvin uh is fully enrolled and and has a device uh enrolled as well so we'll probably try and use that user as well for for this test so we don't have the interconnect client already installed so we're gonna have to go to the browser and navigate to the VPN termination point in this case in My Demo is this and we get the certificate area because we're using cell sign certificate that's fine we'll just advance that and now you can see we've got to the um VPN portal and this is where we need to sign in so you can see our connection profile that we created test dual demo and we're going to sign in now with my user and already I've already received a push notification to my device so I'm just going to accept that and now you can see it's going to sign me in and I've actually received another one already so I've had to use two there and that's because we didn't change the uh VPN um timeout value and we we already know that we we're doing that on the configuration changes is pushing now nevertheless we've signed in here and we can now download the anyconnect client so I'll just download that because it'll be much easier for us to demonstrate the behavior and I'll also share my device that I'm using for two-factor authentication so that you can see the request come through and the the processing full so we'll just install the VPN the anyconnect VPN client here just run through this install okay and we click finish there so that's how I any connect client installed now so we shouldn't need to use the browser anymore for that and if we just head over to the duo Administration panel and we go down to reports we should be able to see that last authentication uh that successful authentication attempt that I've just done to access that and now you can see I received two push notifications and that's because of the timeout value you can see the IP address this is a lab environment so don't worry about that as you also have some other information there as well point is we can see that access is being granted and we can we now know that the two-fact authentication with Duo is in place and up and running and working so we can see now that that change has been made successfully so now we should be able to use the anyconnect client to access our VPN and not receive the two notifications this time we should only see one so I'll just get that open now and you can see it just come up there on the bottom right inside and I'll also share my mobile device as well where we're going to receive the push notification all right so I've got my uh device here with the duo application installed and what we're going to do now is we're going to connect to this VPN so I'll just connect here using the interconnect client and I'm probably actually going to need to change the certificate settings so that we can connect to an untrusted server so let's change this here and let's just connect again and now you can see I can connect so I'm going to connect there and you can see now the um connection profile or the group and I'm going to enter now my username and password and now you can see the Dual authentication because my primary credentials are correct now we should only receive one notification because I set the timeout to 60. so I'll approve that and there you go so that's approved and now you can see on the VPN any connect client we can see that um that's actually failed but you know the process in terms of um connecting is in place now this area is just to do the setting that we've not changed in the VPN policy so we can if you do receive that we can go back and change this so we'll just quickly do this and push a policy again not part of the process but I'll show you this just in case you are new to Firepower or ASA and you are setting this up for the first time just go across to our group policy now let's select the one that we're using and edit that let's go to edit group policy and let's go to any connect and then let's give or create a profile so I'm just going to say test VPN profile and I already have an XML file in here that we can use so I'm just going to add that here and then we'll specify that new profile that we've created and then we'll save that save that again and again we will deploy the changes and this is only if you don't have the I've not configured the VPN before and you need to configure different VPN profiles etc etc you can specify that in the VPN profile editor and then add that to Firepower so that the device is pull that profile and are allowed to connect and you don't see that issue there that we saw a little bit earlier on if you've already got one set up it's like that you've already got these sort of things configured so you may not need to worry about this so I'm just going to now close this VPN client and then we can start again in a moment once that configuration change is being pushed all right so once that change has been pushed again now we should be able to open up any connect client again and this time we should not receive the VPN issue so let's just go to connect again I'll bring up my device and I'll just enter my username and password again and now you can see I've received the request against I'll approve that and let's connect let the uh VPN dates thing and there you go you can see that we've now connected and we already received one push notification because we changed the timeout value as well so we'll just minimize this now and if we go across to our logs and let's just refresh these here you can see that our most recent request has been approved we only received one and that's great so our configuration is set up exactly how we want it now and that is how we can quickly and easily configure a Firepower more Access VPN solution to protect access requests with Duos multi-factor authentication as well [Music]

The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.

Use this transcript

Three free tools that work on the material around a video like this one. No signup, no login.