Trying to log source address of client VPN request, while using Duo Security two-factor proxy server

GregBromley
New here

Trying to log source address of client VPN request, while using Duo Security two-factor proxy server

We are using our Meraki client VPN with the Duo Security proxy server authentication (configured as RADIUS in the Meraki dashboard).  The user connects to the Meraki client VPN as normal, after providing their credentials, the MX sends a request to our Duo proxy server, which authenticates the user to Active Directory and then sends the user a push notification on the mobile device, then tells the MX whether it was successful or not to complete the VPN.

 

The issue we're facing is one user received a push notification to their phone, but had not been attempting to connect to the client VPN, so we are investigating whether her credentials were compromised.  The only issue, is that the MX does not track a source address when a client VPN connection is attempted.  I contacted support and they were able to see the logs sending the request to the Duo proxy, but no source address.  I've checked with Duo as well, but their logs only see what the MX sends to it, which does not have a source address.

 

I asked support if there was any other way of tracking those attempts, I was thinking of an access rule for the traffic on the VPN port, but they said it wouldn't track a successful connection... I thought that was odd.

 

Does anyone know of a way we could track this information on a client VPN connection attempt?

1 Reply 1
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @GregBromley , was the user previously connected via VPN and DUO was re-authenticating the user?

 

I get this when I’m connected into a customers site via VPN.  After a few hours I get a DUO Notification to sign-in again.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels