Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

User Duo lockout SSLVPN

Hello everyone,

We are running into an issue where the SSL VPN client will drop a connection and then cause a DUO lockout after sending multiple auth attempts.

Has anybody found a way to use DUO for SSL (via DUO Radius Server) that will not continually try to reauthenticate the user in their absence?

We have 2FA Duo working just fine until a connection issue occurs and the user is not watching for a Duo push notification. 

We were thinking auto connect set to "no" but that does not seem to help. 

What options in the .ovpn configuration file or on the XGS 4500 running SFOS 20 can we use to correct this behavior?

Ideally, if the client loses connection, we would like for it to wait for the user to initiate the SSLVPN tunnel with a new authentication attempt. 

Is this possible? How do we do it?

Thank you,

Lance



Added v20 TAG
[edited by: Erick Jan at 7:06 AM (GMT -7) on 30 Apr 2024]