{"id":18455,"date":"2026-07-28T14:15:47","date_gmt":"2026-07-28T14:15:47","guid":{"rendered":"https:\/\/www.protectimus.com\/?page_id=18455"},"modified":"2026-07-29T13:06:07","modified_gmt":"2026-07-29T13:06:07","slug":"mfa-for-vpn","status":"publish","type":"page","link":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/","title":{"rendered":"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"18455\" class=\"elementor elementor-18455\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-223acb9 padded e-flex e-con-boxed e-con e-parent\" data-id=\"223acb9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e4740cc elementor-widget elementor-widget-heading\" data-id=\"e4740cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b4a66c0 e-con-full e-flex e-con e-child\" data-id=\"b4a66c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-0870f66 e-con-full e-flex e-con e-child\" data-id=\"0870f66\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e128a97 elementor-widget elementor-widget-text-editor\" data-id=\"e128a97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">VPN credentials have become the most reliable entry point for ransomware groups and state-sponsored attackers alike. A password on a VPN gateway \u2014 without a second factor \u2014 is the functional equivalent of a front door with no deadbolt: technically locked, but not in any way that slows down a determined attacker with a credential list.<\/span><\/p><p><span style=\"font-weight: 400;\">Protectimus adds MFA to any VPN gateway through a RADIUS proxy. Your existing gateway hardware stays exactly as it is. Your users authenticate to the same VPN client they&#8217;ve always used. The second factor appears as an additional step \u2014 a TOTP code from an authenticator app, a hardware token, or an SMS \u2014 before the session is established.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-20c72f6 elementor-widget elementor-widget-html\" data-id=\"20c72f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"BreadcrumbList\",\r\n  \"itemListElement\": [\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 1,\r\n      \"name\": \"Home\",\r\n      \"item\": \"https:\/\/protectimus.com\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 2,\r\n      \"name\": \"Solutions\",\r\n      \"item\": \"https:\/\/protectimus.com\/solutions\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 3,\r\n      \"name\": \"MFA for VPN\",\r\n      \"item\": \"https:\/\/protectimus.com\/mfa-for-vpn\/\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\r\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-42bfc14 e-con-full e-flex e-con e-child\" data-id=\"42bfc14\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6818e9e elementor-widget elementor-widget-heading\" data-id=\"6818e9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Table of Contents<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-282e74f elementor-widget elementor-widget-text-editor\" data-id=\"282e74f\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"why-on-premise-mfa-matters-2026\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#why-vpn-acess\"><span style=\"font-weight: 400;\">Why VPN Access Is the #1 Target in 2026<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#how-protectimus-adds-mfa\"><span style=\"font-weight: 400;\">How Protectimus Adds MFA to VPN Authentication<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supported-vpn-vendors-gateways\"><span style=\"font-weight: 400;\">Supported VPN Vendors &amp; Gateways<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supported-authentication-methods\"><span style=\"font-weight: 400;\">Supported Authentication Methods<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#deployment-options\"><span style=\"font-weight: 400;\">Deployment Options<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#how-add-mfa-to-vpn\"><span style=\"font-weight: 400;\">Step-by-Step: How to Add MFA to Your VPN in 5 Steps<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#compliance\"><span style=\"font-weight: 400;\">Compliance<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#protectimus-vs-other-vpn-mfa\"><span style=\"font-weight: 400;\">Protectimus vs Other VPN MFA Solutions<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#faq\"><span style=\"font-weight: 400;\">FAQ<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#start-securing-your-vpn\"><span style=\"font-weight: 400;\">Start Securing Your VPN Today<\/span><\/a><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b904199 padded e-flex e-con-boxed e-con e-parent\" data-id=\"b904199\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1b1c9bb e-con-full e-flex e-con e-child\" data-id=\"1b1c9bb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f07f411 elementor-widget elementor-widget-heading\" data-id=\"f07f411\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Quick Answer<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-54d9acf elementor-widget elementor-widget-text-editor\" data-id=\"54d9acf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus works as a RADIUS proxy between your VPN gateway and Active Directory or another identity source. When a user connects, the gateway forwards the RADIUS Access-Request to Protectimus, which validates the password against AD\/LDAP and then issues a second-factor challenge. Only after both factors are verified does the gateway receive an Access-Accept and open the tunnel. No gateway replacement, no client-side agents, no changes to your network topology.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cdef92e padded e-flex e-con-boxed e-con e-parent\" data-id=\"cdef92e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56c84d1 elementor-widget elementor-widget-heading\" data-id=\"56c84d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Key facts\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bff780b elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"bff780b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d391a8f e-grid e-con-boxed e-con e-child\" data-id=\"d391a8f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-64a96a2 border-left e-flex e-con-boxed e-con e-child\" data-id=\"64a96a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dfef98 elementor-widget elementor-widget-heading\" data-id=\"4dfef98\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">MFA blocks over 99.2% of automated credential attacks <\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cc1bea elementor-widget elementor-widget-heading\" data-id=\"0cc1bea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Microsoft<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5e29e2 elementor-widget elementor-widget-text-editor\" data-id=\"f5e29e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Microsoft&#8217;s Digital Defense Report 2025 found that enabling MFA eliminates more than 99.2% of automated account compromise attempts \u2014 the highest-impact single control against credential-based attacks. (<\/span><a target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/cybersecurity\/microsoft-digital-defense-report-2025\/\"><span style=\"font-weight: 400;\">Microsoft Digital Defense Report<\/span><\/a><span style=\"font-weight: 400;\">)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f5947b8 border-left e-flex e-con-boxed e-con e-child\" data-id=\"f5947b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa74c1f elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"fa74c1f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-47e43b7 elementor-widget elementor-widget-heading\" data-id=\"47e43b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">73% of network intrusions started through VPN compromise<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb629a4 elementor-widget elementor-widget-heading\" data-id=\"fb629a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">IBM <\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085769 elementor-widget elementor-widget-text-editor\" data-id=\"8085769\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Coalition&#8217;s 2025 Cyber Claims Report found that VPN compromise was the established entry vector in 73% of network intrusions \u2014 highlighting VPN credential compromise as one of the most common initial access methods observed in ransomware-related intrusions. (Coalition 2025 Cyber Claims Report<\/span><span style=\"font-weight: 400;\">)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6c866e elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"c6c866e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5c0d1fa border-left e-flex e-con-boxed e-con e-child\" data-id=\"5c0d1fa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d45db87 elementor-widget elementor-widget-heading\" data-id=\"d45db87\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Credential abuse in 22% of all breaches<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-344d455 elementor-widget elementor-widget-heading\" data-id=\"344d455\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Verizon<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a4d317 elementor-widget elementor-widget-text-editor\" data-id=\"3a4d317\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Verizon DBIR 2026 confirms that stolen credentials remain the #1 initial access vector, present in 22% of confirmed breaches \u2014 with VPN and remote access services consistently listed as primary targets.(<a target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\">Verizon 2026 Data Breach Investigations Report<\/a>)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0ae1e9a padded e-flex e-con-boxed e-con e-parent\" data-id=\"0ae1e9a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e899921 elementor-widget elementor-widget-heading\" data-id=\"e899921\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Key Takeaways<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86d1b8b elementor-widget elementor-widget-spacer\" data-id=\"86d1b8b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d5e935 e-grid e-con-full e-con e-child\" data-id=\"9d5e935\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-12e9470 e-con-full e-flex e-con e-child\" data-id=\"12e9470\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8644d62 elementor-widget elementor-widget-image\" data-id=\"8644d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"57\" height=\"57\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/vpn2.svg\" class=\"attachment-full size-full wp-image-16525\" alt=\"VPN MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-317cba7 elementor-widget elementor-widget-heading\" data-id=\"317cba7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Works with any RADIUS-compatible VPN<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d96a026 elementor-widget elementor-widget-text-editor\" data-id=\"d96a026\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Cisco ASA, Fortinet FortiGate, Palo Alto GlobalProtect, SonicWall, Check Point, Juniper, OpenVPN, MikroTik, and 15+ others.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-68b5ae8 e-con-full e-flex e-con e-child\" data-id=\"68b5ae8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8b57400 elementor-widget elementor-widget-image\" data-id=\"8b57400\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"56\" height=\"60\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/radius1.svg\" class=\"attachment-full size-full wp-image-16522\" alt=\"RADIUS MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-767e2aa elementor-widget elementor-widget-heading\" data-id=\"767e2aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">No gateway replacement<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d73153e elementor-widget elementor-widget-text-editor\" data-id=\"d73153e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus inserts as a RADIUS proxy; existing VPN infrastructure remains in place, with only RADIUS authentication configured.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d3b5b8 e-con-full e-flex e-con e-child\" data-id=\"9d3b5b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89d54f8 elementor-widget elementor-widget-image\" data-id=\"89d54f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"64\" height=\"64\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-ver-tokens.svg\" class=\"attachment-full size-full wp-image-353\" alt=\"Versatile Tokens icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f7f585d elementor-widget elementor-widget-heading\" data-id=\"f7f585d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">TOTP app, SMS, email OTP, chatbot OTP, hardware tokens<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aff0db8 elementor-widget elementor-widget-text-editor\" data-id=\"aff0db8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Multiple second-factor methods to fit different user populations and security policies.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9ddacc7 e-con-full e-flex e-con e-child\" data-id=\"9ddacc7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-82d1654 elementor-widget elementor-widget-image\" data-id=\"82d1654\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"57\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/plat_new.svg\" class=\"attachment-full size-full wp-image-16519\" alt=\"On-premise MFA platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb78c60 elementor-widget elementor-widget-heading\" data-id=\"eb78c60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">On-premises or cloud<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ee318b2 elementor-widget elementor-widget-text-editor\" data-id=\"ee318b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Deploy Protectimus inside your network perimeter or use the cloud service; the On-Premise MFA Platform supports Active Directory and LDAP synchronization, while both deployment options support the same MFA methods and RADIUS integration.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cb9fab9 e-con-full e-flex e-con e-child\" data-id=\"cb9fab9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b3c387 elementor-widget elementor-widget-image\" data-id=\"1b3c387\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"64\" height=\"64\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2025\/03\/key-5.svg\" class=\"attachment-full size-full wp-image-12236\" alt=\"On-Premise MFA Platform \u2013 Security feature: A Cluster-Based, Fault-Tolerant System\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-84c6048 elementor-widget elementor-widget-heading\" data-id=\"84c6048\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">One server secures all VPNs<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1abcc56 elementor-widget elementor-widget-text-editor\" data-id=\"1abcc56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A single Protectimus RADIUS proxy can serve multiple VPN gateways simultaneously.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7c15682 e-con-full e-flex e-con e-child\" data-id=\"7c15682\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffb514c elementor-widget elementor-widget-image\" data-id=\"ffb514c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-check.svg\" class=\"attachment-full size-full wp-image-637\" alt=\"Customer Stories section icon \u2013 real-life client experiences\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3382fca elementor-widget elementor-widget-heading\" data-id=\"3382fca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Deploy in one day<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-785b26a elementor-widget elementor-widget-text-editor\" data-id=\"785b26a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Standard single-gateway deployments complete in under 8 hours from installation to live enforcement.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30a9584 elementor-widget elementor-widget-spacer\" data-id=\"30a9584\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5b50e5c padded e-flex e-con-boxed e-con e-parent\" data-id=\"5b50e5c\" data-element_type=\"container\" data-e-type=\"container\" id=\"why-vpn-acess\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-28b1e56 e-con-full e-flex e-con e-child\" data-id=\"28b1e56\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6f90e4 elementor-widget elementor-widget-heading\" data-id=\"a6f90e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Why VPN Access Is the #1 Target in 2026<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d2498b elementor-widget elementor-widget-text-editor\" data-id=\"9d2498b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The pattern is consistent across every major threat intelligence report published in the last two years: attackers go for VPN first, because VPN is the front door to everything else.<\/span><\/p><p><span style=\"font-weight: 400;\">A successful VPN authentication puts an attacker inside the network with the same access as a legitimate remote employee. From that position they can reach file shares, internal applications, domain controllers, and every other resource that isn&#8217;t additionally segmented. The cost of a VPN credential \u2014 measured in what it unlocks \u2014 is enormous relative to the effort required to obtain one.<\/span><\/p><p><span style=\"font-weight: 400;\">Credential stuffing is the primary technique. Billions of username\/password pairs from historical breaches circulate freely on criminal forums. Automated tools cycle through these lists against VPN endpoints continuously. Even a 0.1% success rate against a large credential list produces hundreds of working sessions.<\/span><\/p><p><span style=\"font-weight: 400;\">The threat actor landscape targeting VPN credentials is no longer just opportunistic criminals. Rapid7 and Cisco PSIRT documented that ransomware groups Akira and LockBit ran sustained brute-force campaigns specifically targeting Cisco ASA VPN endpoints in 2025. GreyNoise observed over 25,000 unique IP addresses scanning Cisco ASA login portals in a single campaign spike in August 2025. CISA has issued emergency directives for critical vulnerabilities in Fortinet, Ivanti, and Cisco VPN products in the last 18 months \u2014 in each case, attackers targeted the VPN authentication layer through credential attacks, authentication bypasses, or vulnerabilities affecting the VPN gateway itself.<\/span><\/p><p><span style=\"font-weight: 400;\">Software vulnerabilities get patched. Credential-based attacks don&#8217;t require an unpatched appliance \u2014 they just require that the target accepts passwords without a second factor.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-63ef710 padded e-flex e-con-boxed e-con e-parent\" data-id=\"63ef710\" data-element_type=\"container\" data-e-type=\"container\" id=\"how-protectimus-adds-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-09d136e e-con-full e-flex e-con e-child\" data-id=\"09d136e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-28b6260 elementor-widget elementor-widget-heading\" data-id=\"28b6260\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How Protectimus Adds MFA to VPN Authentication<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9959746 elementor-widget elementor-widget-text-editor\" data-id=\"9959746\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The architecture is a RADIUS proxy insertion. Protectimus sits between your VPN gateway and your existing directory (Active Directory or LDAP), receiving authentication requests and enforcing a second factor before returning an Access-Accept.<\/p><p>\u00a0<\/p><h3>Authentication flow<\/h3><div style=\"max-width: 620px; margin: 30px 0; font-family: Arial, sans-serif;\"><div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\"><strong>User<\/strong><br \/><small>VPN Client<\/small><\/div><div style=\"width: 460px; text-align: center; margin: 8px 0;\"><small style=\"color: #666;\">Enters username and password<\/small><div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\">\u00a0<\/div><div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div><\/div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\"><strong>VPN Gateway<\/strong><br \/><small>Cisco AnyConnect \/ FortiGate \/ GlobalProtect \/ etc.<\/small><\/div><div style=\"width: 460px; text-align: center; margin: 8px 0;\"><small style=\"color: #666;\">RADIUS Access-Request<\/small><div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\">\u00a0<\/div><div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div><\/div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\"><strong>Protectimus RADIUS Server<\/strong><br \/><small>Validates password via AD \/ LDAP<\/small><br \/><br \/><small><strong>Returns Access-Challenge (OTP Prompt)<\/strong><\/small><\/div><div style=\"width: 460px; text-align: center; margin: 8px 0;\"><small style=\"color: #666;\">OTP prompt is displayed<\/small><div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\">\u00a0<\/div><div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div><\/div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\"><strong>User<\/strong><br \/><small>Enters a one-time password<\/small><\/div><div style=\"width: 460px; text-align: center; margin: 8px 0;\"><small style=\"color: #666;\">RADIUS Access-Request (OTP)<\/small><div style=\"width: 2px; height: 18px; background: #111; margin: 4px auto 0;\">\u00a0<\/div><div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div><\/div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.35) 0%, rgba(123,225,255,.18) 45%, rgba(123,225,255,0) 100%); text-align: center;\"><strong>Protectimus RADIUS Server<\/strong><br \/><small>Validates OTP<\/small><br \/><br \/><small><strong>Returns Access-Accept<\/strong><\/small><\/div><div style=\"width: 460px; text-align: center; margin: 8px 0;\"><div style=\"width: 2px; height: 18px; background: #111; margin: 0 auto;\">\u00a0<\/div><div style=\"font-size: 13px; line-height: 10px;\">\u25bc<\/div><\/div><div style=\"width: 460px; box-sizing: border-box; padding: 16px 20px; border: 1px solid #111111; background: linear-gradient(135deg, rgba(123,225,255,.60) 0%, rgba(123,225,255,.38) 45%, rgba(123,225,255,.08) 100%); text-align: center;\"><strong>VPN Gateway<\/strong><br \/><small>Secure VPN session established<\/small><\/div><\/div><\/div><p>\u00a0<\/p><h3><span style=\"font-weight: 400;\">Access-Challenge vs Inline Mode<\/span><\/h3><p>Most modern VPN clients \u2014 Cisco AnyConnect, Fortinet SSL VPN client, Palo Alto GlobalProtect \u2014 support RADIUS Access-Challenge natively. After entering their password, the user sees a secondary OTP prompt within the VPN client interface. This is the cleanest user experience and requires no changes to the client configuration.<\/p><p>For legacy VPN clients or gateway firmware versions that don&#8217;t correctly handle Access-Challenge, Protectimus provides <b>Inline Mode<\/b><span style=\"font-weight: 400;\">. The user enters their password and OTP in a single authentication field, separated by a configurable delimiter (for example: <\/span><span style=\"font-weight: 400;\">MyPassword,123456<\/span><span style=\"font-weight: 400;\">). Protectimus parses the combined input, validates each component separately, and returns the appropriate response. Inline Mode works with virtually any RFC 2865-compliant RADIUS client.<\/span><\/p><p>One operational note: the default RADIUS timeout on many VPN gateways is 5 seconds \u2014 designed for instant password validation, not for a user retrieving a TOTP code. Increase this to at least 30 seconds on the gateway side before going live. One of the most common causes of failed test deployments is leaving the default RADIUS timeout unchanged.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d57877c padded e-flex e-con-boxed e-con e-parent\" data-id=\"d57877c\" data-element_type=\"container\" data-e-type=\"container\" id=\"supported-vpn-vendors-gateways\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1698709 e-con-full e-flex e-con e-child\" data-id=\"1698709\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-88c2197 elementor-widget elementor-widget-heading\" data-id=\"88c2197\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Supported VPN &amp; Remote Access Platforms<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83f93dd elementor-widget elementor-widget-text-editor\" data-id=\"83f93dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus has documented and tested integrations with the following VPN gateways, remote access platforms, and RADIUS-enabled solutions. Any RFC 2865-compliant RADIUS client can also be integrated, even if not listed below.<\/span><\/p><p>\u00a0<\/p><table><tbody><tr><td><p><b>Vendor<\/b><\/p><\/td><td><p><b>Platform \/ Product<\/b><\/p><\/td><td><p><b>Integration Guide<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Array Networks<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">AG SSL VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/array-ag-ssl-vpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Instructions<\/span><\/a><\/p><\/td><\/tr><tr><td>Aruba<\/td><td><p><span style=\"font-weight: 400;\">ClearPass<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/aruba-clearpass-2fa\/\">Configuration Guide<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Barracuda<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">SSL VPN<\/span><\/p><\/td><td><a href=\"https:\/\/www.protectimus.com\/es\/guides\/barracuda-ssl-vpn-2fa\/\">Setup Guide<\/a><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Check Point<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Mobile Access<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/check-point-vpn-2fa\/\">Integration Steps<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cisco<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">AnyConnect (ASA, Firepower FTD)<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/cisco-anyconnect\/\">Configuration Guide<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cisco<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Meraki Client VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/cisco-meraki-client-vpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Instructions<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cisco<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Switches (RADIUS Authentication)<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/cisco-switches-2fa\/\">Setup Guide<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Citrix<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">ADC \/ Gateway<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/citrix-adc-and-gateway\/\">Integration Guide<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">F5<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">BIG-IP APM<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/f5-big-ip-apm-vpn-2fa\/\">Configuration Steps<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Forcepoint<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/forcepoint-vpn-2fa\/\">Setup Guide<\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Fortinet<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">FortiGate VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/fortigate-vpn-2fa\/\"><span style=\"font-weight: 400;\">Configuration Guide<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Ivanti<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Connect Secure (formerly Pulse Connect Secure)<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/pulse-connect-secure-ssl-vpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Instructions<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Juniper<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/juniper-vpn-2fa\/\"><span style=\"font-weight: 400;\">Integration Steps<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">MikroTik<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">RouterOS VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/mikrotik-vpn-2fa\/\"><span style=\"font-weight: 400;\">Configuration Guide<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Microsoft<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Windows Server VPN (RRAS)<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/windows-vpn-2fa\/\"><span style=\"font-weight: 400;\">Guide Link<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">NComputing<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">vSpace<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/ncomputing-vspace-2fa\/\"><span style=\"font-weight: 400;\">Configuration Steps<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">NetApp<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">VDS<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/netapp-virtual-desktop-service-2fa\/\"><span style=\"font-weight: 400;\">Integration Guide<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Nerdio<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Nerdio<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/nerdio-2fa\/\"><span style=\"font-weight: 400;\">Guide Link<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">OpenVPN<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">OpenVPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/openvpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Guide Link<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Netgate<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">pfSense (OpenVPN)<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/pfsense-openvpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Instructions<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Palo Alto Networks<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">GlobalProtect<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/palo-alto-globalprotect-vpn-2fa\/\"><span style=\"font-weight: 400;\">Integration Steps<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Parallels<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">RAS<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/parallels-ras-mfa\/\"><span style=\"font-weight: 400;\">Guide Link<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">SonicWall<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/sonicwall-vpn-2fa\/\"><span style=\"font-weight: 400;\">Setup Guide<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">VMware<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Horizon View<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/vmware-horizon-view-2fa\/\"><span style=\"font-weight: 400;\">Configuration Guide<\/span><\/a><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">WatchGuard<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Mobile VPN<br \/><\/span><\/p><\/td><td><a href=\"https:\/\/www.protectimus.com\/es\/guides\/watchguard-mobile-vpn-2fa\/\">Setup Instructions<\/a><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p><p><span style=\"font-weight: 400;\">For a complete overview of Protectimus <\/span><a href=\"https:\/\/www.protectimus.com\/es\/radius-authentication\/\"><span style=\"font-weight: 400;\">RADIUS authentication with MFA<\/span><\/a><span style=\"font-weight: 400;\"> for VPN, VDI, Wi-Fi, and other RADIUS-enabled services, see the dedicated RADIUS page. For the <\/span><a href=\"https:\/\/www.protectimus.com\/es\/radius\/\"><span style=\"font-weight: 400;\">Protectimus RADIUS component<\/span><\/a><span style=\"font-weight: 400;\"> product page with installation details and system requirements, see the RADIUS component page.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-86abc7e padded e-flex e-con-boxed e-con e-parent\" data-id=\"86abc7e\" data-element_type=\"container\" data-e-type=\"container\" id=\"supported-authentication-methods\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-f0f2e30 e-con-full e-flex e-con e-child\" data-id=\"f0f2e30\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-684bcff elementor-widget elementor-widget-heading\" data-id=\"684bcff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Supported Authentication Methods<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b52e3d elementor-widget elementor-widget-text-editor\" data-id=\"4b52e3d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><thead><tr><th><p><b>Method<\/b><\/p><\/th><th><p><b>How it delivers the OTP<\/b><\/p><\/th><th><p><b>Best for<\/b><\/p><\/th><th><p><b>Works without internet on user device<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><a href=\"https:\/\/www.protectimus.com\/es\/token\/smart\/\"><b>TOTP via Protectimus SMART app<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Authenticator app that generates 30-second codes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Most enterprise users with smartphones<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/es\/tokens\/\"><b>Hardware TOTP tokens<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Physical device generates codes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Air-gapped environments, users without smartphones, high-security roles<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/es\/token\/sms\/\"><b>SMS OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">6-digit code via SMS<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Users without smartphones or reliable Internet access<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No (requires mobile signal)<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/es\/token\/mail\/\"><b>Email OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">6-digit code via email<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations that prefer email-based OTP delivery<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/www.protectimus.com\/es\/token\/bot\/\"><b>Chatbot OTP<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">OTP via Telegram or Viber bot<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Organizations looking for a convenient, low-cost alternative to SMS OTP<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p><p><b>VPN-specific consideration:<\/b><span style=\"font-weight: 400;\"> methods that require an active internet connection on the user&#8217;s device (SMS, email, chatbot) work for most VPN users since they typically have connectivity before connecting. TOTP via authenticator app and hardware tokens work even when the user&#8217;s device has no network connection \u2014 the code is generated locally and doesn&#8217;t require any external service.<\/span><\/p><p><span style=\"font-weight: 400;\">For users who need physical <\/span><a href=\"https:\/\/www.protectimus.com\/es\/tokens\/\"><span style=\"font-weight: 400;\">hardware TOTP tokens<\/span><\/a><span style=\"font-weight: 400;\"> \u2014 whether due to device restrictions, compliance requirements, or personal preference \u2014 Protectimus supports Slim NFC, TWO, FLEX, and SHARK models, as well as any OATH TOTP\/HOTP\/OCRA-compatible third-party token.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-280411b padded e-flex e-con-boxed e-con e-parent\" data-id=\"280411b\" data-element_type=\"container\" data-e-type=\"container\" id=\"deployment-options\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2bd5d59 e-con-full e-flex e-con e-child\" data-id=\"2bd5d59\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-347cae5 elementor-widget elementor-widget-heading\" data-id=\"347cae5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Deployment Options<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3977085 elementor-widget elementor-widget-text-editor\" data-id=\"3977085\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"font-weight: 400;\">Cloud RADIUS MFA service<\/span><\/h3><p><span style=\"font-weight: 400;\">Protectimus Cloud MFA Service works together with the Protectimus RADIUS Server. Your VPN gateway authenticates users against the Protectimus RADIUS Server, which securely communicates with the Protectimus Cloud MFA Service to validate the second factor. This deployment eliminates the need to host your own MFA platform while keeping deployment simple and lightweight.<\/span><\/p><h3><span style=\"font-weight: 400;\">On-premises RADIUS MFA server<\/span><\/h3><p><span style=\"font-weight: 400;\">The Protectimus RADIUS Server installs on a Windows or Linux server inside your network. All RADIUS traffic stays on-premises. When used with the Protectimus On-Premise MFA Platform, you can also synchronize users from Active Directory or LDAP for centralized identity management. Suitable for organizations with data residency requirements, air-gapped networks, or security policies that prohibit cloud authentication services. See the\u00a0 <\/span><a href=\"https:\/\/www.protectimus.com\/es\/platform\/\"><span style=\"font-weight: 400;\">on-premises MFA platform<\/span><\/a><span style=\"font-weight: 400;\"> page for deployment specs.<\/span><\/p><h3><span style=\"font-weight: 400;\">High availability<\/span><\/h3><p><span style=\"font-weight: 400;\">In on-premises deployments, the Protectimus Platform can be deployed as a multi-node cluster. Since the Protectimus RADIUS Server is installed on each platform node, RADIUS authentication benefits from the same high-availability architecture. When using the Protectimus Cloud MFA Service, high availability can be achieved by deploying redundant Protectimus RADIUS Server instances.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a29b829 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a29b829\" data-element_type=\"container\" data-e-type=\"container\" id=\"how-add-mfa-to-vpn\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1dc9ec2 e-con-full e-flex e-con e-child\" data-id=\"1dc9ec2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-131348d elementor-widget elementor-widget-heading\" data-id=\"131348d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Step-by-Step: How to Add MFA to Your VPN in 5 Steps<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5266633 elementor-widget elementor-widget-text-editor\" data-id=\"5266633\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"supported-mfa-methods\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Step 1 \u2014 Deploy Protectimus.<\/b><span style=\"font-weight: 400;\"> Choose the Protectimus Cloud MFA Service or the Protectimus On-Premise MFA Platform. If you choose the Cloud MFA Service, create an account at service.protectimus.com, then install and configure the Protectimus RADIUS Server on a Windows or Linux server inside your network. If you choose the On-Premise Platform, install both the platform and the Protectimus RADIUS Server.<\/span><\/p><p><b>Step 2 \u2014 Configure the RADIUS client on your gateway.<\/b><span style=\"font-weight: 400;\"> Add Protectimus as a RADIUS server in your gateway&#8217;s AAA configuration. Set the server IP, shared secret, and authentication port (UDP 1812). Set the RADIUS timeout to at least 30 seconds.<\/span><\/p><p><b>Step 3 \u2014 Point the gateway to Protectimus.<\/b><span style=\"font-weight: 400;\"> Update the authentication server reference in your VPN tunnel group or connection profile to use the Protectimus RADIUS Server. Configure the appropriate authentication provider (LDAP, Active Directory, RADIUS Proxy, or another supported option) in the Protectimus RADIUS Server.<\/span><\/p><p><b>Step 4 \u2014 Configure users. <\/b><span style=\"font-weight: 400;\">If you are using the Protectimus On-Premise Platform, configure Active Directory or LDAP synchronization and import users from the required organizational units or security groups. If you are using the Protectimus Cloud MFA Service, add users manually.<\/span><\/p><p><b>Step 5 \u2014 Enroll users and test.<\/b><span style=\"font-weight: 400;\"> Send self-enrollment links to a pilot group. Users scan a QR code to register their authenticator app or authenticate using an assigned hardware token. Test the full flow: connect via VPN, enter credentials, verify the OTP prompt appears, confirm the session opens with a valid code. Then extend to the full user population.<\/span><\/p><p><span style=\"font-weight: 400;\">For vendor-specific screenshots and CLI commands, use the integration guide links in the vendor table above.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-16797b4 padded e-flex e-con-boxed e-con e-parent\" data-id=\"16797b4\" data-element_type=\"container\" data-e-type=\"container\" id=\"compliance\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-bb86bc5 e-con-full e-flex e-con e-child\" data-id=\"bb86bc5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-891beb3 elementor-widget elementor-widget-heading\" data-id=\"891beb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Compliance<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7f6098 elementor-widget elementor-widget-text-editor\" data-id=\"d7f6098\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3):<\/b><span style=\"font-weight: 400;\"> Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment from outside the organization&#8217;s network \u2014 VPN access is the primary scenario in scope. Requirement 8.4.2 extends this to all CDE access regardless of connection method.<\/span><\/p><p><b>NIST SP 800-63B (AAL2):<\/b><span style=\"font-weight: 400;\"> Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 directly.<\/span><\/p><p><b>HIPAA (45 CFR \u00a7 164.312):<\/b><span style=\"font-weight: 400;\"> Technical Safeguards require access controls for systems containing electronic protected health information. MFA for VPN access helps organizations meet the access control requirements of this safeguard.<\/span><\/p><p><b>NIS2 Directive (Article 21):<\/b><span style=\"font-weight: 400;\"> Essential and important entities must implement multi-factor or continuous authentication for access to network and information systems. VPN MFA covers the remote access scenarios explicitly called out in ENISA implementation guidance.<\/span><\/p><p><b>ISO\/IEC 27001:2022 (Annex A 8.5):<\/b><span style=\"font-weight: 400;\"> Secure authentication controls explicitly recommended for remote access and privileged account scenarios.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dd147b2 padded e-flex e-con-boxed e-con e-parent\" data-id=\"dd147b2\" data-element_type=\"container\" data-e-type=\"container\" id=\"protectimus-vs-other-vpn-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-c9b7b25 e-con-full e-flex e-con e-child\" data-id=\"c9b7b25\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fad9de1 elementor-widget elementor-widget-heading\" data-id=\"fad9de1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Protectimus vs Other VPN MFA Solutions<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-78865c0 elementor-widget elementor-widget-text-editor\" data-id=\"78865c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><thead><tr><th><p><b>Factor<\/b><\/p><\/th><th><p><b>Protectimus<\/b><\/p><\/th><th><p><b>Duo Security<\/b><\/p><\/th><th><p><b>Azure MFA \/ NPS Extension<\/b><\/p><\/th><th><p><b>RSA SecurID<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Deployment model<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cloud or on-premises<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cloud (proxy on-prem)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cloud (Entra ID required)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cloud or on-premises<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">RADIUS support<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Native proxy<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Via Duo Authentication Proxy<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Via NPS Extension<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Native<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Agent required on gateway<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No (NPS Extension on NPS server)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Hardware token support<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Full OATH TOTP\/HOTP<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Limited<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Limited (P1\/P2 license required)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">RSA tokens only<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Air-gapped environments<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes (on-prem)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes (on-prem)<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Direct on-prem AD (no Entra)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Via proxy\/agent<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Requires Entra ID Connect<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Yes<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Pricing model<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Per-user subscription<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Per-user subscription<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Included in Entra ID P1\/P2<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Per-user license<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Vendor lock-in<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Independent<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cisco\/Duo ecosystem<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Microsoft ecosystem<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">RSA ecosystem<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p><p><span style=\"font-weight: 400;\">The comparison is factual. Duo works well for organizations already standardized on the Cisco\/Duo stack. Azure MFA NPS Extension is the lowest-friction choice for organizations with Entra ID P1\/P2 licenses already in place. RSA SecurID suits environments with existing RSA infrastructure. Protectimus is the strongest choice when on-premises deployment, full hardware token support, or independence from a specific vendor ecosystem is required.<\/span><\/p><p><span style=\"font-weight: 400;\">Learn more about protecting Active Directory with MFA on our <\/span><a href=\"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/\"><span style=\"font-weight: 400;\">MFA for Active Directory<\/span><\/a><span style=\"font-weight: 400;\"> page.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a9cb282 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a9cb282\" data-element_type=\"container\" data-e-type=\"container\" id=\"faq\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7659ffd elementor-widget elementor-widget-heading\" data-id=\"7659ffd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dc81e4c e-con-full padded e-flex e-con e-child\" data-id=\"dc81e4c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-fb2596d e-con-full faq-container e-flex e-con e-child\" data-id=\"fb2596d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-412fa06 plus-right elementor-widget elementor-widget-n-accordion\" data-id=\"412fa06\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;all_collapsed&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6830\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6830\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Does it work without replacing my VPN gateway? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6830\" class=\"elementor-element elementor-element-ea1991a e-con-full e-flex e-con e-child\" data-id=\"ea1991a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8bad61c elementor-widget elementor-widget-text-editor\" data-id=\"8bad61c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. Protectimus operates as a RADIUS proxy \u2014 your gateway keeps its existing configuration and continues talking RADIUS exactly as before, just to a different server IP. No firmware updates, no hardware changes, no downtime during the cutover.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6831\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6831\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> What if my VPN client has no separate OTP field? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6831\" class=\"elementor-element elementor-element-b2bdc68 e-con-full e-flex e-con e-child\" data-id=\"b2bdc68\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f30747e elementor-widget elementor-widget-text-editor\" data-id=\"f30747e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Use Inline Mode. The user enters their password and OTP in a single field with a configured separator (for example, a comma or a specific character). Protectimus parses the combined input and validates each part separately. This works with any RADIUS client, including legacy configurations that predate challenge\/response support.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6832\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6832\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Can I secure multiple VPN gateways with one Protectimus server? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6832\" class=\"elementor-element elementor-element-0787040 e-con-full e-flex e-con e-child\" data-id=\"0787040\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9eb7aff elementor-widget elementor-widget-text-editor\" data-id=\"9eb7aff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. Register each gateway as a separate RADIUS client in Protectimus with its own shared secret. All gateways point to the same Protectimus RADIUS endpoint. User enrollments are shared \u2014 a user&#8217;s registered token works across all gateways from a single enrollment.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6833\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6833\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Does it support high availability? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6833\" class=\"elementor-element elementor-element-b3373c0 e-con-full e-flex e-con e-child\" data-id=\"b3373c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ef49d2 elementor-widget elementor-widget-text-editor\" data-id=\"6ef49d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. Deploy redundant Protectimus RADIUS Servers and configure your VPN gateway to fail over automatically if the primary server becomes unavailable. When using the Protectimus On-Premise MFA Platform, the platform can also be deployed as a high-availability cluster.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6834\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6834\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Is there an on-premises option? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6834\" class=\"elementor-element elementor-element-3e2c10e e-con-full e-flex e-con e-child\" data-id=\"3e2c10e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1ee304 elementor-widget elementor-widget-text-editor\" data-id=\"e1ee304\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes. Protectimus offers an On-Premise MFA Platform that is deployed entirely within your own infrastructure. It can be installed on a single server or as a high-availability cluster, with all authentication processing remaining inside your network. See the\u00a0 <\/span><a href=\"https:\/\/www.protectimus.com\/es\/platform\/\"><span style=\"font-weight: 400;\">on-premises MFA platform<\/span><\/a><span style=\"font-weight: 400;\"> page for system requirements and deployment options.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6835\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6835\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> Which hardware tokens work with VPN MFA? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6835\" class=\"elementor-element elementor-element-67bff32 e-con-full e-flex e-con e-child\" data-id=\"67bff32\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ed5da62 elementor-widget elementor-widget-text-editor\" data-id=\"ed5da62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Any OATH TOTP, OCRA or HOTP-compatible hardware token. Protectimus offers four\u00a0 TOTP tokens models \u2014 Slim NFC (card format, programmable), TWO (classic key fob, SHA-1), FLEX (key fob, programmable), SHARK (classic key fob, SHA-256) \u2014 as well as compatibility with third-party OATH tokens from other manufacturers. See\u00a0 <\/span><a href=\"https:\/\/www.protectimus.com\/es\/tokens\/\"><span style=\"font-weight: 400;\">hardware TOTP tokens<\/span><\/a><span style=\"font-weight: 400;\"> for the full list.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6836\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"7\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6836\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> How long does VPN MFA deployment take? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6836\" class=\"elementor-element elementor-element-a41023b e-con-full e-flex e-con e-child\" data-id=\"a41023b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2a36881 elementor-widget elementor-widget-text-editor\" data-id=\"2a36881\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A single-gateway deployment \u2014 one AD directory, one VPN gateway, standard TOTP method \u2014 typically completes in under 8 hours from start to live enforcement, including user pilot testing. Multi-gateway and multi-domain environments take longer depending on the number of integrations; the RADIUS configuration itself is the same for each gateway.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Does it work without replacing my VPN gateway?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Protectimus operates as a RADIUS proxy \\u2014 your gateway keeps its existing configuration and continues talking RADIUS exactly as before, just to a different server IP. No firmware updates, no hardware changes, no downtime during the cutover.\"}},{\"@type\":\"Question\",\"name\":\"What if my VPN client has no separate OTP field?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Use Inline Mode. The user enters their password and OTP in a single field with a configured separator (for example, a comma or a specific character). Protectimus parses the combined input and validates each part separately. This works with any RADIUS client, including legacy configurations that predate challenge\\\/response support.\"}},{\"@type\":\"Question\",\"name\":\"Can I secure multiple VPN gateways with one Protectimus server?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Register each gateway as a separate RADIUS client in Protectimus with its own shared secret. All gateways point to the same Protectimus RADIUS endpoint. User enrollments are shared \\u2014 a user&#8217;s registered token works across all gateways from a single enrollment.\"}},{\"@type\":\"Question\",\"name\":\"Does it support high availability?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Deploy redundant Protectimus RADIUS Servers and configure your VPN gateway to fail over automatically if the primary server becomes unavailable. When using the Protectimus On-Premise MFA Platform, the platform can also be deployed as a high-availability cluster.\"}},{\"@type\":\"Question\",\"name\":\"Is there an on-premises option?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Protectimus offers an On-Premise MFA Platform that is deployed entirely within your own infrastructure. It can be installed on a single server or as a high-availability cluster, with all authentication processing remaining inside your network. See the\\u00a0 on-premises MFA platform page for system requirements and deployment options.\"}},{\"@type\":\"Question\",\"name\":\"Which hardware tokens work with VPN MFA?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Any OATH TOTP, OCRA or HOTP-compatible hardware token. Protectimus offers four\\u00a0 TOTP tokens models \\u2014 Slim NFC (card format, programmable), TWO (classic key fob, SHA-1), FLEX (key fob, programmable), SHARK (classic key fob, SHA-256) \\u2014 as well as compatibility with third-party OATH tokens from other manufacturers. See\\u00a0 hardware TOTP tokens for the full list.\"}},{\"@type\":\"Question\",\"name\":\"How long does VPN MFA deployment take?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A single-gateway deployment \\u2014 one AD directory, one VPN gateway, standard TOTP method \\u2014 typically completes in under 8 hours from start to live enforcement, including user pilot testing. Multi-gateway and multi-domain environments take longer depending on the number of integrations; the RADIUS configuration itself is the same for each gateway.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7534fb4 elementor-widget elementor-widget-html\" data-id=\"7534fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"HowTo\",\r\n  \"name\": \"How to Set Up MFA for Cisco AnyConnect with Protectimus\",\r\n  \"description\": \"Step-by-step setup of multi-factor authentication for Cisco AnyConnect VPN using Protectimus via RADIUS: platform setup, RADIUS Server installation and configuration, ASA\/Firepower AAA configuration, AnyConnect connection profile, and user enrollment. First authentication with MFA enforced is achievable within 2\u20134 hours for a standard single-domain deployment.\",\r\n  \"totalTime\": \"PT4H\",\r\n  \"estimatedCost\": {\r\n    \"@type\": \"MonetaryAmount\",\r\n    \"currency\": \"USD\",\r\n    \"value\": \"0\"\r\n  },\r\n  \"supply\": [\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Cisco ASA or Firepower Threat Defense appliance with AnyConnect VPN configured\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Active Directory, LDAP, or local user directory for primary credential validation\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Linux or Windows server for the Protectimus RADIUS Server (or for the full On-Premise Platform)\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Network connectivity: UDP 1812\/1813 between ASA and RADIUS Server\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Administrative access to Cisco ASDM or Firepower Management Center (FMC)\"\r\n    }\r\n  ],\r\n  \"tool\": [\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus Cloud Service or Protectimus On-Premise Platform\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus RADIUS Server\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Cisco ASDM or Firepower Management Center (FMC)\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus SMART OTP app, hardware token (Slim NFC, TWO, FLEX, SHARK), or Protectimus BOT\"\r\n    }\r\n  ],\r\n  \"step\": [\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 1,\r\n      \"name\": \"Set up the Protectimus platform or cloud service\",\r\n      \"text\": \"Register at protectimus.com for the cloud service, or install the Protectimus On-Premise Platform on your infrastructure. In the platform, create a Resource representing the AnyConnect VPN integration and note your API URL, Login, and API Key \u2014 they are required for the RADIUS Server configuration.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-1\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/1.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 2,\r\n      \"name\": \"Install and configure the Protectimus RADIUS Server\",\r\n      \"text\": \"Install the Protectimus RADIUS Server on a Linux host (recommended) or Windows server accessible from the ASA. Edit the radius.yml configuration file with your Protectimus API credentials, RADIUS shared secret, ASA client IP, LDAP\/AD connection parameters, and listening port (UDP 1812). Start the RADIUS service and confirm it is listening. Verify firewall rules allow UDP 1812 and 1813 from the ASA to the RADIUS Server.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-2\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/2.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 3,\r\n      \"name\": \"Configure the Cisco ASA AAA Server Group\",\r\n      \"text\": \"In Cisco ASDM, navigate to Configuration \u2192 Remote Access VPN \u2192 AAA\/Local Users \u2192 AAA Server Groups. Add a new AAA Server Group named 'protectimus' with Protocol set to RADIUS. Set Accounting Mode to Single, Reactivation Mode to Depletion, Dead Time 10, Max Failed Attempts 3. Add the Protectimus RADIUS Server with its IP, authentication port 1816, accounting port 1815, timeout 10s, and the matching shared secret. For Cisco Firepower via FMC, the equivalent path is Objects \u2192 Object Management \u2192 RADIUS Server Group \u2192 Add Group with identical parameters.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-3\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/3.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 4,\r\n      \"name\": \"Configure the AnyConnect VPN connection\",\r\n      \"text\": \"In Cisco ASDM, open Wizards \u2192 VPN Wizards \u2192 AnyConnect VPN Wizard. Configure the connection profile name, VPN access interface, enable SSL and IPsec, and select or generate a device certificate. Add AnyConnect client image (.pkg) files. In the Authentication Methods step, select the 'protectimus' AAA Server Group. In the SAML Configuration step, set Authentication Method to AAA, select the protectimus AAA Server Group, leave SAML Server as None. Configure the client IP address pool and DNS settings, enable 'Exempt VPN traffic from network address translation' and 'Allow Web Launch', then review and finish.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-4\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/4.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 5,\r\n      \"name\": \"Enroll users and assign OTP tokens\",\r\n      \"text\": \"Add users to the Protectimus platform manually, via CSV import, or via LDAP sync with Active Directory. Assign tokens (Protectimus SMART OTP app, hardware tokens, or chatbot OTP) to users manually, or activate the Self-Service Portal so users can enroll and manage their own tokens. Run authentication tests with a pilot group before broader rollout.\",\r\n      \"url\": \"https:\/\/protectimus.com\/mfa-for-cisco-anyconnect\/#step-5\",\r\n      \"image\": \"https:\/\/protectimus.com\/wp-content\/uploads\/2024\/07\/5.svg\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fe2c5b0 padded e-flex e-con-boxed e-con e-parent\" data-id=\"fe2c5b0\" data-element_type=\"container\" data-e-type=\"container\" id=\"start-securing-your-vpn\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e4ec716 e-con-full e-flex e-con e-child\" data-id=\"e4ec716\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-35746bf e-con-full e-flex e-con e-child\" data-id=\"35746bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-489bd70 e-con-full e-flex e-con e-child\" data-id=\"489bd70\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10cf0aa elementor-widget elementor-widget-heading\" data-id=\"10cf0aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Start Securing Your VPN Today<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c0eeb4 elementor-widget elementor-widget-text-editor\" data-id=\"6c0eeb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Every day a VPN endpoint accepts passwords without a second factor, it&#8217;s a target. Protectimus adds MFA to your VPN in one day without replacing your gateway or disrupting your users.<\/span><\/p><p><b>Free for up to 10 users, with a $25 testing credit \u2014 no credit card required.<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><strong><a target=\"_blank\" target=\"_blank\" href=\"https:\/\/service.protectimus.com\/register\/\">Start free \u2192 service.protectimus.com<\/a><\/strong><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><strong><a href=\"https:\/\/www.protectimus.com\/es\/platform\/\">On-premises deployment \u2192 Protectimus Platform<\/a><\/strong><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><strong><a href=\"https:\/\/www.protectimus.com\/es\/radius-authentication\/\">Full RADIUS MFA guide \u2192 RADIUS authentication with MFA<\/a><\/strong><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a3f81ec e-con-full contact-us-bg e-flex e-con e-child\" data-id=\"a3f81ec\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fb3d121 elementor-widget elementor-widget-shortcode\" data-id=\"fb3d121\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"container\" data-elementor-id=\"17554\" class=\"elementor elementor-17554 elementor-3585\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3a82e0d1 e-con-full e-flex e-con e-child\" data-id=\"3a82e0d1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b4de036 elementor-widget elementor-widget-image\" data-id=\"b4de036\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"370\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/05\/contact-seal.svg\" class=\"attachment-full size-full wp-image-17583\" alt=\"Send Us A Message icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1bc85d61 elementor-widget elementor-widget-heading\" data-id=\"1bc85d61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Env\u00edenos un mensaje<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cf09046 elementor-widget elementor-widget-shortcode\" data-id=\"cf09046\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f17553-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"17553\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/es\/wp-json\/wp\/v2\/pages\/18455#wpcf7-f17553-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"17553\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.2\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f17553-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/>\n<\/fieldset>\n<div class=\"protectimus-form\">\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"uname\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Nombre\" value=\"\" type=\"text\" name=\"uname\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Correo electr\u00f3nico\" value=\"\" type=\"email\" name=\"email\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"subject\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Asunto\" value=\"\" type=\"text\" name=\"subject\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"message\"><textarea cols=\"40\" rows=\"1\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Mensaje\" name=\"message\"><\/textarea><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col mb-2\">\n        <input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Enviar\" \/>\n    <\/div>\n<\/div>\n\n<\/div><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-311ad2c e-grid e-con-full equal-height equal-height-mob e-con e-child\" data-id=\"311ad2c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<a target=\"_blank\" target=\"_blank\" class=\"elementor-element elementor-element-feb2bbc e-con-full four-link e-flex e-con e-child\" data-id=\"feb2bbc\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/service.protectimus.com\/en\/register\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f27e21b eq-height elementor-widget elementor-widget-heading\" data-id=\"f27e21b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Start free trial<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-76c9612 elementor-widget elementor-widget-image\" data-id=\"76c9612\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-4ccade8 e-con-full four-link e-flex e-con e-child\" data-id=\"4ccade8\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/www.protectimus.com\/es\/contact-us\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-45ea78d eq-height elementor-widget elementor-widget-heading\" data-id=\"45ea78d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Contact sales<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e65f9a1 elementor-widget elementor-widget-image\" data-id=\"e65f9a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-c9d4aa4 e-con-full four-link e-flex e-con e-child\" data-id=\"c9d4aa4\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/es\/pricing\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b9e4eb6 eq-height elementor-widget elementor-widget-heading\" data-id=\"b9e4eb6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Pricing details<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-120f334 elementor-widget elementor-widget-image\" data-id=\"120f334\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-e82cb51 e-con-full four-link e-flex e-con e-child\" data-id=\"e82cb51\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/es\/guides\/saas-service\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d33e100 eq-height elementor-widget elementor-widget-heading\" data-id=\"d33e100\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Integration guides<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3de24d6 elementor-widget elementor-widget-image\" data-id=\"3de24d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway VPN credentials have become the most reliable entry point for ransomware groups and state-sponsored attackers alike. A password on a VPN gateway \u2014 without a second factor \u2014 is the functional equivalent of a front door with no deadbolt: technically locked, but not in any [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"class_list":["post-18455","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"google-site-verification\" content=\"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"PROTECTIMUS\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"MFA for VPN: Two-Factor Authentication for Any VPN Gateway\" \/>\n\t\t<meta property=\"og:description\" content=\"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-28T14:15:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-29T13:06:07+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"MFA for VPN: Two-Factor Authentication for Any VPN Gateway\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"accounts@vipertop.com\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#listItem\",\"name\":\"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#listItem\",\"position\":2,\"name\":\"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\",\"name\":\"Protectimus\",\"description\":\"Two-Factor Authentication Provider\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"telephone\":\"+17867966664\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/logo-icon.svg\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#organizationLogo\",\"width\":72,\"height\":51,\"caption\":\"Protectimus logo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#organizationLogo\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#webpage\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/\",\"name\":\"MFA for VPN: Two-Factor Authentication for Any VPN Gateway\",\"description\":\"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN & 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.\",\"inLanguage\":\"es-ES\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-vpn\\\/#breadcrumblist\"},\"datePublished\":\"2026-07-28T14:15:47+00:00\",\"dateModified\":\"2026-07-29T13:06:07+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"name\":\"PROTECTIMUS\",\"inLanguage\":\"es-ES\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>MFA for VPN: Two-Factor Authentication for Any VPN Gateway<\/title>\n\n","aioseo_head_json":{"title":"MFA for VPN: Two-Factor Authentication for Any VPN Gateway","description":"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN & 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.","canonical_url":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","position":1,"name":"Home","item":"https:\/\/www.protectimus.com\/es\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#listItem","name":"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#listItem","position":2,"name":"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway","previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/www.protectimus.com\/es\/#organization","name":"Protectimus","description":"Two-Factor Authentication Provider","url":"https:\/\/www.protectimus.com\/es\/","telephone":"+17867966664","logo":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/logo-icon.svg","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#organizationLogo","width":72,"height":51,"caption":"Protectimus logo"},"image":{"@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#organizationLogo"}},{"@type":"WebPage","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#webpage","url":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/","name":"MFA for VPN: Two-Factor Authentication for Any VPN Gateway","description":"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN & 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.","inLanguage":"es-ES","isPartOf":{"@id":"https:\/\/www.protectimus.com\/es\/#website"},"breadcrumb":{"@id":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/#breadcrumblist"},"datePublished":"2026-07-28T14:15:47+00:00","dateModified":"2026-07-29T13:06:07+00:00"},{"@type":"WebSite","@id":"https:\/\/www.protectimus.com\/es\/#website","url":"https:\/\/www.protectimus.com\/es\/","name":"PROTECTIMUS","inLanguage":"es-ES","publisher":{"@id":"https:\/\/www.protectimus.com\/es\/#organization"}}]},"og:locale":"es_ES","og:site_name":"PROTECTIMUS","og:type":"article","og:title":"MFA for VPN: Two-Factor Authentication for Any VPN Gateway","og:description":"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.","og:url":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/","og:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","og:image:secure_url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","article:published_time":"2026-07-28T14:15:47+00:00","article:modified_time":"2026-07-29T13:06:07+00:00","twitter:card":"summary_large_image","twitter:title":"MFA for VPN: Two-Factor Authentication for Any VPN Gateway","twitter:description":"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.","twitter:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","twitter:label1":"Written by","twitter:data1":"accounts@vipertop.com","twitter:label2":"Est. reading time","twitter:data2":"14 minutes"},"aioseo_meta_data":{"post_id":"18455","title":"MFA for VPN: Two-Factor Authentication for Any VPN Gateway","description":"Add MFA to any VPN: Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN &amp; 20+ more. RADIUS proxy, no gateway changes. On-prem or cloud. Free for 10 users.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-07-29 14:35:08","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-28 02:01:46","updated":"2026-07-29 14:35:08"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/es\/\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tMFA for VPN: Add Two-Factor Authentication to Any VPN Gateway\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.protectimus.com\/es\/"},{"label":"MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway","link":"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/"}],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/comments?post=18455"}],"version-history":[{"count":19,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18455\/revisions"}],"predecessor-version":[{"id":18507,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18455\/revisions\/18507"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/media?parent=18455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}