How to enforce 2 Factor Authentication on user login?

Enable the following settings to Enforce two FA on user ssh login as well as for the web interface. This will prompt the ssh gateway user to set two factor authentication before going ahead and is a recommended security setting.

multi factor authentication

 

Enable the different 2 factor mechanisms that will be available for the gateway user for setup. 

Two factor Authentication tab is available only from version 7.11.0. If you are running a old version, then 2fa methods configured under Settings->General->Security tab will be available.

2 factor authentications

 

Relogin, into the webgui and the user will be prompted to setup the 2 factor method if he hasn't setup any. Setup any one 2fa method of your choice from here.

setup 2FA

 

If you want to setup more 2fa methods, then after logging into the webgui, setup multiple 2fa methods here.

2factor mechanism used for the last login into the webgui would be the 2fa method in use in the backend. To change, the 2fa method in use in the backend,  login into the webgui using the new 2fa method so that it becomes the default 2fa method for the backend.

2fa setup

 

We have setup Google 2fa and Access Keyword successfully and would be prompted for it. In the example below, we are using Google 2fa to login and hence the same would be prompted in the backend shell as well.

2fa methods

 

The backend would looks as follows..

google 2fa

 

 

 

 

 

 

 

 

 

 

0 (0)
Article Rating (No Votes)
Rate this article
    Attached Files
    There are no attachments for this article.
    Related Articles RSS Feed
    How to change the private key in use and change the default public key in use?
    Viewed 2274 times since Fri, Dec 1, 2017
    Set SSH User Expiry
    Viewed 952 times since Thu, Sep 20, 2018
    configure ssh-tunnel on jump server or bastion host
    Viewed 1133 times since Fri, May 11, 2018
    How do I prevent the root password of the target server that i add from being changed?
    Viewed 1566 times since Wed, Jun 14, 2017
    Configure DUO 2FA in Ezeelogin SSH jumphost
    Viewed 1904 times since Thu, Nov 23, 2017
    Configure ssh timeout in ssh gateway
    Viewed 2145 times since Fri, Dec 1, 2017
    How to ensure that password are not recorded when ssh session recording is enabled to meet security compliances like PCI DSS 3.2 , HIPAA, SOX, SOC2, FFIEC, NERC CIP, ISO 27001 ?
    Viewed 1520 times since Fri, Mar 2, 2018
    Access Keyword 2FA explained
    Viewed 369 times since Wed, Jan 30, 2019
    Can Network switches be added as a device and managed?
    Viewed 1491 times since Thu, Jun 15, 2017
    Password management and the different options.
    Viewed 1794 times since Wed, Jun 14, 2017