top of page

Parrot Discussion Group

Public·406 members

Anna Schmidt
Anna Schmidt

MFA Implementation Requirements for Cisco VPN

Has anyone recently audited their AnyConnect deployment specifically for dual-factor enforcement? We are updating our remote access policies and I am looking for independent assessments regarding backend authentication configurations for ASA gateways.

8 Views

The main issue with AnyConnect is that it does not have native second factor tools. It just drops credentials to whatever backend you configured on ASA or Firepower. If that backend checks only passwords then any stolen data opens the gate. Hackers use simple phishing or infostealers to get in and we see this in recent report statistics for Akira or LockBit campaigns. We had to deal with this recently and we used guides like https://www.protectimus.com/mfa-for-cisco-anyconnect/ to figure out how to lock this down properly through the authentication backend. Adding an actual second factor is basically the only way to stop these attacks because passwords alone do not work anymore.

Members

  • juel hezronjuel hezron
    juel hezron
  • Grace
    Grace
  • Carol Lawrence
    Carol Lawrence
  • Donald Trumps
    Donald Trumps
  • Nathan
    Nathan
bottom of page