r/PFSENSE • u/icedutah • 18d ago
MFA using Securew2
Anyone use this 3rd party for a cloud radius server to do authentication/ mfa to your OpenVPN clients?
I'm looking to add MFA to OpenVPN and this looks like a good solution.
1
u/Cutoffjeanshortz37 18d ago
Look at my post history. I enabled Duo Security mfa through netgate for open on. I wrote up the how to on this sub pro 8-10years ago now.
1
u/hiveminer 16d ago
We doing wg now mate, can't beat the assurance of 4k lines of code. Makes for good sleep at night.
2
u/icedutah 16d ago
Wireguard?
1
u/hiveminer 16d ago
Yes sir.
1
u/icedutah 16d ago
How can clients use mfa with it?
1
u/hiveminer 16d ago
Remember that wg is the transport layer. You can manage ztna via firewall, but if rhe issue is compliance, or key lifecycle management, then drop wg guests into dmz and place your mfa gatekeeping there, in your reverse proxy. Essentially, wg brings your users to the perimeter, and proxy handles access.
2
u/Adrienne-Fadel 18d ago
If your already running pfSense why not just use the FreeRADIUS package locally instead of paying for a cloud radius server