VPN Clients and secure key usb

Teddy_fr
Comes here often

VPN Clients and secure key usb

Hi all,

 

I successfully configured the Meraki VPN (on MERAKI MX100) with a shared security key and email/password for each user and native Windows client. But would it be possible to increase security using a USB authentication key or Microsoft Authenticator on a smartphone?

4 Replies 4
Mloraditch
Kind of a big deal
Kind of a big deal

Not with just the native authentication. You need to either use radius or more ideally get licensed for Secure Client (AnyConnect) that will have a better end user experience

One example For Microsoft Authenticator with Radius:
https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Client...
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension



 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

To add to @Mloraditch answer, I haven't done an AnyConnect+RADIUS deployment for 2 years now.  Everyone wants SAML, because that allows you to natively authenticate against Entra ID.

 

And if you are using Entra ID, you can use a FIDO2 key, such as a YubiKey, or Microsoft Authenticator.

https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Client...

 

Brash
Kind of a big deal
Kind of a big deal

The native Windows client is pretty limited in its support for additional security features.

As said above, if you use Microsoft Entra, you can enable MFA via the MFA extension and conditional access.

Teddy_fr
Comes here often

Ok, thank you for all 🙂

Get notified when there are additional replies to this discussion.