Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Openvpn + 2FA

    Scheduled Pinned Locked Moved OpenVPN
    3 Posts 2 Posters 211 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      nick.loenders
      last edited by

      I have a client who has a local domain (windows servers 2019) and a Netgate 4200.
      On the Netgate I setup an openvpn server, so they can connect safely to the network when working from home.
      The Netgate is connected to the domain with a LDAP connection, so the users can use the username and password to login to the vpn connection.
      All good so far.
      Now they want to use a 2FA solution as an extra security option. (eg Microsoft authenticator app on the smartphone)

      To do this, do I really need to setup a NPS on a server? or can I just activate a 2FA method on the method (maybe when I create local users on the Netgate, so without LDAP)

      And in either case, where do I find a recent tutorial?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @nick.loenders
        last edited by

        @nick.loenders

        Scroll down a bit ?!
        Stop here : "How to configure true 2FA (LDAP + Google Authenticator OTP) for OpenVPN on pfSense?".

        No "help me" PM's please. Use the forum, the community will thank you.

        N 1 Reply Last reply Reply Quote 0
        • N Offline
          nick.loenders @Gertjan
          last edited by

          @Gertjan It was an 80% good manual, and I got it working when the username is created manually in the FreeRadius service. But when using ldap and freeradius, the 2FA stops working. Then you need NPS or DuoSecurity... and it is a whole different ballgame.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.