{"id":18589,"date":"2026-07-02T11:39:03","date_gmt":"2026-07-02T11:39:03","guid":{"rendered":"https:\/\/www.protectimus.com\/radius-authentication\/"},"modified":"2026-08-27T19:08:20","modified_gmt":"2026-08-27T19:08:20","slug":"radius-authentication","status":"publish","type":"page","link":"https:\/\/www.protectimus.com\/es\/radius-authentication\/","title":{"rendered":"Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"18589\" class=\"elementor elementor-18589 elementor-18138\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-223acb9 padded e-flex e-con-boxed e-con e-parent\" data-id=\"223acb9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e4740cc elementor-widget elementor-widget-heading\" data-id=\"e4740cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b4a66c0 e-con-full e-flex e-con e-child\" data-id=\"b4a66c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-0870f66 e-con-full e-flex e-con e-child\" data-id=\"0870f66\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e128a97 elementor-widget elementor-widget-text-editor\" data-id=\"e128a97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>RADIUS \u2014el protocolo que gestiona silenciosamente la autenticaci\u00f3n de la mayor\u00eda de las VPN corporativas, redes Wi-Fi e infraestructuras de red\u2014 se dise\u00f1\u00f3 en otra \u00e9poca. Cumple su funci\u00f3n con fiabilidad: un dispositivo de red env\u00eda credenciales a un servidor RADIUS, el servidor las verifica contra un directorio, y se concede o deniega el acceso. Lo que no hace es comprobar que la persona que introduce esas credenciales sea realmente quien dice ser. Una contrase\u00f1a robada vale exactamente igual que una leg\u00edtima.<\/p><p>A\u00f1adir MFA a RADIUS cierra esa brecha. En lugar de sustituir su infraestructura existente, un proxy RADIUS se sit\u00faa entre sus dispositivos de red y su directorio, exigiendo un segundo factor en cada solicitud de autenticaci\u00f3n antes de emitir un Access-Accept.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-20c72f6 elementor-widget elementor-widget-html\" data-id=\"20c72f6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"BreadcrumbList\",\r\n  \"itemListElement\": [\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 1,\r\n      \"name\": \"Home\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 2,\r\n      \"name\": \"Solutions\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/solutions\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 3,\r\n      \"name\": \"RADIUS Authentication with MFA\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/radius-authentication\/\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-42bfc14 e-con-full e-flex e-con e-child\" data-id=\"42bfc14\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6818e9e elementor-widget elementor-widget-heading\" data-id=\"6818e9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">\u00cdndice<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-282e74f elementor-widget elementor-widget-text-editor\" data-id=\"282e74f\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"why-on-premise-mfa-matters-2026\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#what-is-radius\"><span style=\"font-weight: 400;\">Qu\u00e9 es la autenticaci\u00f3n RADIUS y por qu\u00e9 necesita MFA<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#how-protectimus-adds-mfa\"><span style=\"font-weight: 400;\">C\u00f3mo a\u00f1ade Protectimus la MFA a la autenticaci\u00f3n RADIUS<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supported-mfa-methods\"><span style=\"font-weight: 400;\">M\u00e9todos de MFA compatibles con RADIUS<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supported-radius-equip\"><span style=\"font-weight: 400;\">Clientes RADIUS y equipos de red compatibles<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#radius-mfa-for-vpn\"><span style=\"font-weight: 400;\">RADIUS MFA para VPN<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#radius-mfa-for-wlan-access\"><span style=\"font-weight: 400;\">RADIUS MFA para el acceso a redes inal\u00e1mbricas<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#deployment-opt\"><span style=\"font-weight: 400;\">Opciones de implementaci\u00f3n<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#system-requirements\"><span style=\"font-weight: 400;\">Requisitos del sistema e integraci\u00f3n<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#radius-setup\"><span style=\"font-weight: 400;\">Paso a paso: c\u00f3mo configurar RADIUS MFA en 5 pasos<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#radius-mfa-compliance\"><span style=\"font-weight: 400;\">Cumplimiento: c\u00f3mo RADIUS MFA satisface los requisitos normativos<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#radius-mfa-faq\"><span style=\"font-weight: 400;\">Preguntas frecuentes<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#get-protected\"><span style=\"font-weight: 400;\">Empiece a proteger el acceso a su red hoy mismo<\/span><\/a><\/li>\n<\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-b904199 padded e-flex e-con-boxed e-con e-parent\" data-id=\"b904199\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1b1c9bb e-con-full e-flex e-con e-child\" data-id=\"1b1c9bb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f07f411 elementor-widget elementor-widget-heading\" data-id=\"f07f411\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Respuesta r\u00e1pida<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-54d9acf elementor-widget elementor-widget-text-editor\" data-id=\"54d9acf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">RADIUS (Remote Authentication Dial-In User Service) es la columna vertebral del control de acceso a la red en la mayor\u00eda de los entornos empresariales, gestionando la autenticaci\u00f3n de VPN, Wi-Fi corporativo, dispositivos de acceso a la red, NPS y puertas de enlace VDI. El propio protocolo, definido en la <\/span><a target=\"_blank\" target=\"_blank\" href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc2865\"><span style=\"font-weight: 400;\">RFC 2865<\/span><\/a><span style=\"font-weight: 400;\">, se dise\u00f1\u00f3 d\u00e9cadas antes de que los ataques basados en credenciales se convirtieran en la norma. A\u00f1adir MFA sobre RADIUS hoy significa insertar un segundo paso de verificaci\u00f3n entre el dispositivo de red y su directorio, sin sustituir su infraestructura existente. Protectimus funciona como un proxy RADIUS: su firewall Cisco, su puerta de enlace Fortinet o su firewall Palo Alto siguen hablando RADIUS exactamente igual que antes, mientras se aplica un segundo factor en la capa de proxy antes de emitir un RADIUS Access-Accept.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cdef92e padded e-flex e-con-boxed e-con e-parent\" data-id=\"cdef92e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56c84d1 elementor-widget elementor-widget-heading\" data-id=\"56c84d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Datos clave<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bff780b elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"bff780b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d391a8f e-grid e-con-boxed e-con e-child\" data-id=\"d391a8f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-64a96a2 border-left e-flex e-con-boxed e-con e-child\" data-id=\"64a96a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dfef98 elementor-widget elementor-widget-heading\" data-id=\"4dfef98\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Las credenciales son el vector de ataque n\u00ba 1<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cc1bea elementor-widget elementor-widget-heading\" data-id=\"0cc1bea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">FACT<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5e29e2 elementor-widget elementor-widget-text-editor\" data-id=\"f5e29e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Los ataques basados en credenciales \u2014incluidos el phishing, el credential stuffing y el password spraying\u2014 figuran de forma constante entre los principales vectores de acceso inicial en las brechas de red, siendo los endpoints VPN un objetivo primario.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f5947b8 border-left e-flex e-con-boxed e-con e-child\" data-id=\"f5947b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa74c1f elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"fa74c1f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-47e43b7 elementor-widget elementor-widget-heading\" data-id=\"47e43b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">AAL2 exige MFA<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb629a4 elementor-widget elementor-widget-heading\" data-id=\"fb629a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">NIST<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6c866e elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"c6c866e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085769 elementor-widget elementor-widget-text-editor\" data-id=\"8085769\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">El Nivel de Garant\u00eda de Autenticador 2 (AAL2) de NIST SP 800-63B exige expl\u00edcitamente autenticaci\u00f3n multifactor para cualquier acceso de red a sistemas sensibles.<\/span><\/p><p><span style=\"font-weight: 400;\">(<a target=\"_blank\" target=\"_blank\" href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\">NIST Special Publication 800-63B<\/a>)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5c0d1fa border-left e-flex e-con-boxed e-con e-child\" data-id=\"5c0d1fa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d45db87 elementor-widget elementor-widget-heading\" data-id=\"d45db87\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">La infraestructura VPN est\u00e1 bajo ataque<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-344d455 elementor-widget elementor-widget-heading\" data-id=\"344d455\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">CISA<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a4d317 elementor-widget elementor-widget-text-editor\" data-id=\"3a4d317\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">El aviso de CISA sobre seguridad VPN se\u00f1ala que los atacantes se dirigen habitualmente a la infraestructura de acceso remoto precisamente porque a menudo carece de un segundo factor de autenticaci\u00f3n.<\/span><\/p><p><span style=\"font-weight: 400;\">(<a target=\"_blank\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-025a\">CISA&#8217;s advisories<\/a>)<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0ae1e9a padded e-flex e-con-boxed e-con e-parent\" data-id=\"0ae1e9a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e899921 elementor-widget elementor-widget-heading\" data-id=\"e899921\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Ventajas clave<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86d1b8b elementor-widget elementor-widget-spacer\" data-id=\"86d1b8b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d5e935 e-grid e-con-full e-con e-child\" data-id=\"9d5e935\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-12e9470 e-con-full e-flex e-con e-child\" data-id=\"12e9470\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8644d62 elementor-widget elementor-widget-image\" data-id=\"8644d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"56\" height=\"60\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/radius1.svg\" class=\"attachment-full size-full wp-image-16522\" alt=\"RADIUS MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-317cba7 elementor-widget elementor-widget-heading\" data-id=\"317cba7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">No requiere cambios de infraestructura<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d96a026 elementor-widget elementor-widget-text-editor\" data-id=\"d96a026\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Protectimus funciona como un proxy RADIUS; sus puertas de enlace VPN, controladores inal\u00e1mbricos y conmutadores de red existentes conservan su configuraci\u00f3n.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-68b5ae8 e-con-full e-flex e-con e-child\" data-id=\"68b5ae8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8b57400 elementor-widget elementor-widget-image\" data-id=\"8b57400\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"64\" height=\"64\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2025\/03\/key-5.svg\" class=\"attachment-full size-full wp-image-17649\" alt=\"On-Premise MFA Platform \u2013 Security feature: A Cluster-Based, Fault-Tolerant System\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-767e2aa elementor-widget elementor-widget-heading\" data-id=\"767e2aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Implementaci\u00f3n r\u00e1pida<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d73153e elementor-widget elementor-widget-text-editor\" data-id=\"d73153e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Muchas organizaciones pueden implementar RADIUS MFA en un solo d\u00eda laborable, seg\u00fan la complejidad de la infraestructura y los requisitos de integraci\u00f3n.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d3b5b8 e-con-full e-flex e-con e-child\" data-id=\"9d3b5b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89d54f8 elementor-widget elementor-widget-image\" data-id=\"89d54f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"28\" height=\"28\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/03\/icon-radius.svg\" class=\"attachment-full size-full wp-image-17322\" alt=\"MFA for RADIUS icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f7f585d elementor-widget elementor-widget-heading\" data-id=\"f7f585d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Independiente del proveedor<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aff0db8 elementor-widget elementor-widget-text-editor\" data-id=\"aff0db8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Integraciones documentadas y probadas con Cisco ASA\/FTD, Juniper, Fortinet FortiGate, Palo Alto GlobalProtect, SonicWall, Check Point, F5 y muchas otras plataformas.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9ddacc7 e-con-full e-flex e-con e-child\" data-id=\"9ddacc7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-82d1654 elementor-widget elementor-widget-image\" data-id=\"82d1654\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-windows.svg\" class=\"attachment-full size-full wp-image-547\" alt=\"MFA for Windows and RDP icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb78c60 elementor-widget elementor-widget-heading\" data-id=\"eb78c60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Sincronizaci\u00f3n completa con AD\/LDAP<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ee318b2 elementor-widget elementor-widget-text-editor\" data-id=\"ee318b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>El aprovisionamiento de usuarios, las pol\u00edticas de grupo y las b\u00fasquedas en el directorio se obtienen de su Active Directory o LDAP existente.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cb9fab9 e-con-full e-flex e-con e-child\" data-id=\"cb9fab9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b3c387 elementor-widget elementor-widget-image\" data-id=\"1b3c387\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"57\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/plat_new.svg\" class=\"attachment-full size-full wp-image-16519\" alt=\"On-premise MFA platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-84c6048 elementor-widget elementor-widget-heading\" data-id=\"84c6048\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">On-premises o en la nube<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1abcc56 elementor-widget elementor-widget-text-editor\" data-id=\"1abcc56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Existen opciones de implementaci\u00f3n que permiten a las organizaciones elegir la arquitectura que mejor se adapte a sus requisitos de seguridad y operativos.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7c15682 e-con-full e-flex e-con e-child\" data-id=\"7c15682\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffb514c elementor-widget elementor-widget-image\" data-id=\"ffb514c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"57\" height=\"57\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/vpn2.svg\" class=\"attachment-full size-full wp-image-16525\" alt=\"VPN MFA icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3382fca elementor-widget elementor-widget-heading\" data-id=\"3382fca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Dise\u00f1ado para VPN<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-785b26a elementor-widget elementor-widget-text-editor\" data-id=\"785b26a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">y otros escenarios de acceso remoto basados en RADIUS.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30a9584 elementor-widget elementor-widget-spacer\" data-id=\"30a9584\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5b50e5c padded e-flex e-con-boxed e-con e-parent\" data-id=\"5b50e5c\" data-element_type=\"container\" data-e-type=\"container\" id=\"what-is-radius\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-28b1e56 e-con-full e-flex e-con e-child\" data-id=\"28b1e56\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6f90e4 elementor-widget elementor-widget-heading\" data-id=\"a6f90e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Qu\u00e9 es la autenticaci\u00f3n RADIUS y por qu\u00e9 necesita MFA<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d2498b elementor-widget elementor-widget-text-editor\" data-id=\"9d2498b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>RADIUS es un protocolo cliente\/servidor que centraliza la autenticaci\u00f3n, autorizaci\u00f3n y registro (AAA) para el acceso a la red. Cuando un usuario se conecta a una VPN, se autentica en el Wi-Fi corporativo o inicia sesi\u00f3n en un conmutador a trav\u00e9s de una interfaz de gesti\u00f3n, el dispositivo de red (llamado NAS, Network Access Server) env\u00eda un paquete <strong>Access-Request<\/strong> al servidor RADIUS. Ese servidor valida las credenciales y responde con uno de tres mensajes: <strong>Access-Accept<\/strong> (permitir el acceso), <strong>Access-Reject<\/strong> (denegar) o <strong>Access-Challenge<\/strong> (solicitar informaci\u00f3n adicional, como un OTP).<\/p><p>Es un protocolo ordenado y probado a lo largo del tiempo. Pero su dise\u00f1o original asum\u00eda que una combinaci\u00f3n v\u00e1lida de usuario y contrase\u00f1a era prueba suficiente de identidad. En 2026, esa suposici\u00f3n es insostenible.<\/p><p> <\/p><h3><span style=\"font-weight: 400;\">Por qu\u00e9 las contrase\u00f1as por s\u00ed solas no protegen los servicios autenticados por RADIUS<\/span><\/h3><p>El <b>credential stuffing<\/b> <span style=\"font-weight: 400;\">es el ataque que quita el sue\u00f1o a los equipos de seguridad de red. Los atacantes compran o recopilan listas de pares usuario\/contrase\u00f1a filtrados \u2014miles de millones de ellos se comercian libremente en foros criminales\u2014 y automatizan los intentos de inicio de sesi\u00f3n contra los endpoints VPN. La mayor\u00eda de las puertas de enlace VPN no tienen pol\u00edticas de bloqueo lo bastante estrictas como para detener los ataques lentos y sostenidos. Incluso una tasa de \u00e9xito del 0,5% frente a una lista de 50.000 credenciales entrega a los atacantes 250 sesiones VPN v\u00e1lidas.<\/span><\/p><p>El <b>password spraying<\/b> <span style=\"font-weight: 400;\">es la variante m\u00e1s silenciosa: en lugar de atacar una sola cuenta, los atacantes prueban una contrase\u00f1a com\u00fan<\/span> (<em>como<\/em> <em>Autumn2024!<\/em><span style=\"font-weight: 400;\">) contra miles de cuentas. Elude la mayor\u00eda de los umbrales de bloqueo de cuentas y resulta casi invisible en los registros.<\/span><\/p><p><span style=\"font-weight: 400;\">M\u00e1s all\u00e1 de los ataques indiscriminados, los atacantes dirigidos usan el phishing para recolectar credenciales de dominio y luego pivotan directamente hacia el acceso VPN o Wi-Fi, eludiendo por completo las defensas perimetrales.<\/span><\/p><p><span style=\"font-weight: 400;\">RADIUS en s\u00ed no tiene ning\u00fan mecanismo para exigir un segundo factor. Transmite las credenciales a un directorio backend, recibe un Accept\/Reject y ah\u00ed termina la conversaci\u00f3n. Una forma habitual de a\u00f1adir MFA a RADIUS es desplegar un proxy RADIUS que intercepta el Access-Request, valida la contrase\u00f1a con el sistema ascendente y luego exige un desaf\u00edo de OTP antes de emitir un Access-Accept.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d57877c padded e-flex e-con-boxed e-con e-parent\" data-id=\"d57877c\" data-element_type=\"container\" data-e-type=\"container\" id=\"how-protectimus-adds-mfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1698709 e-con-full e-flex e-con e-child\" data-id=\"1698709\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-88c2197 elementor-widget elementor-widget-heading\" data-id=\"88c2197\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">C\u00f3mo a\u00f1ade Protectimus la MFA a la autenticaci\u00f3n RADIUS<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83f93dd elementor-widget elementor-widget-text-editor\" data-id=\"83f93dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<span style=\"font-weight: 400;\">La arquitectura es deliberadamente sencilla. El servidor RADIUS de Protectimus se sit\u00faa entre su dispositivo de red y su backend RADIUS\/AD existente como <\/span><b>RADIUS proxy<\/b><span style=\"font-weight: 400;\">. El dispositivo de red no sabe que algo ha cambiado; simplemente env\u00eda su Access-Request a una direcci\u00f3n IP distinta. Desde el lado de AD, el servidor de Protectimus se autentica contra el directorio usando la contrase\u00f1a del usuario exactamente igual que siempre.<\/span>\n<br\/><br\/><h3>Flujo de autenticaci\u00f3n<\/h3>\n<div style=\"max-width:620px;margin:30px 0;font-family:Arial,sans-serif;\">\n\n<div>\n\n<div style=\"width:460px;box-sizing:border-box;padding:16px 20px;border:1px solid #111111;background:linear-gradient(135deg,rgba(123,225,255,.35) 0%,rgba(123,225,255,.18) 45%,rgba(123,225,255,0) 100%);text-align:center;\">\n<strong>Usuario<\/strong><br\/><small>Cliente VPN \/ Wi-Fi<\/small>\n<\/div>\n\n<div style=\"width:460px;text-align:center;margin:8px 0;\">\n<small style=\"color:#666;\">Access-Request (usuario + contrase\u00f1a)<\/small>\n<div style=\"width:2px;height:18px;background:#111;margin:4px auto 0;\"><\/div>\n<div style=\"font-size:13px;line-height:10px;\">\u25bc<\/div>\n<\/div>\n\n<div style=\"width:460px;box-sizing:border-box;padding:16px 20px;border:1px solid #111111;background:linear-gradient(135deg,rgba(123,225,255,.35) 0%,rgba(123,225,255,.18) 45%,rgba(123,225,255,0) 100%);text-align:center;\">\n<strong>Dispositivo de red<\/strong><br\/><small>Cisco ASA \/ FortiGate \/ UniFi, etc.<\/small>\n<\/div>\n\n<div style=\"width:460px;text-align:center;margin:8px 0;\">\n<small style=\"color:#666;\">RADIUS Access-Request<\/small>\n<div style=\"width:2px;height:18px;background:#111;margin:4px auto 0;\"><\/div>\n<div style=\"font-size:13px;line-height:10px;\">\u25bc<\/div>\n<\/div>\n\n<div style=\"width:460px;box-sizing:border-box;padding:16px 20px;border:1px solid #111111;background:linear-gradient(135deg,rgba(123,225,255,.35) 0%,rgba(123,225,255,.18) 45%,rgba(123,225,255,0) 100%);text-align:center;\">\n<strong>Servidor RADIUS de Protectimus<\/strong><br\/><small>Valida la contrase\u00f1a v\u00eda AD \/ LDAP<\/small><br\/><br\/><small><strong>Devuelve Access-Challenge (OTP)<\/strong><\/small>\n<\/div>\n\n<div style=\"width:460px;text-align:center;margin:8px 0;\">\n<small style=\"color:#666;\">El usuario introduce el OTP<\/small>\n<div style=\"width:2px;height:18px;background:#111;margin:4px auto 0;\"><\/div>\n<div style=\"font-size:13px;line-height:10px;\">\u25bc<\/div>\n<\/div>\n\n<div style=\"width:460px;box-sizing:border-box;padding:16px 20px;border:1px solid #111111;background:linear-gradient(135deg,rgba(123,225,255,.35) 0%,rgba(123,225,255,.18) 45%,rgba(123,225,255,0) 100%);text-align:center;\">\n<strong>Servidor RADIUS de Protectimus<\/strong><br\/><small>Valida el OTP<\/small><br\/><br\/><small><strong>Devuelve Access-Accept<\/strong><\/small>\n<\/div>\n\n<div style=\"width:460px;text-align:center;margin:8px 0;\">\n<div style=\"width:2px;height:18px;background:#111;margin:0 auto;\"><\/div>\n<div style=\"font-size:13px;line-height:10px;\">\u25bc<\/div>\n<\/div>\n\n\n<div style=\"width:460px;box-sizing:border-box;padding:16px 20px;border:1px solid #111111;background:linear-gradient(135deg,rgba(123,225,255,.60) 0%,rgba(123,225,255,.38) 45%,rgba(123,225,255,.08) 100%);text-align:center;\"><strong>Dispositivo de red<\/strong>\n<small>Sesi\u00f3n de usuario establecida<\/small><\/div>\n\n\n<\/div>\n\n<\/div>\n<br><p><b>Paso 1: comprobaci\u00f3n de credenciales.<\/b> Protectimus reenv\u00eda la contrase\u00f1a del usuario a Active Directory o LDAP para la autenticaci\u00f3n principal. Si la contrase\u00f1a falla, la solicitud se rechaza de inmediato. No se emite ning\u00fan aviso de MFA para las contrase\u00f1as fallidas, lo que evita los ataques de enumeraci\u00f3n.<\/p>\n\n<p><b>Paso 2: desaf\u00edo de MFA.<\/b> Tras una comprobaci\u00f3n de contrase\u00f1a exitosa, Protectimus env\u00eda un Access-Challenge de vuelta al dispositivo de red con un aviso para el segundo factor. El usuario introduce su c\u00f3digo TOTP desde la app de MFA, un token OTP hardware, o un OTP por chatbot\/SMS\/email.<\/p>\n\n<p><b>Paso 3: aceptar o rechazar.<\/b> Si el segundo factor se valida, se emite un Access-Accept. Si no, un Access-Reject. El dispositivo de red aplica el resultado.<\/p>\n\n<p>Una nota t\u00e9cnica importante: el flujo de Access-Challenge requiere que el dispositivo NAS admita el challenge\/response de RADIUS. La mayor\u00eda de los clientes VPN modernos (Cisco AnyConnect, Fortinet SSL VPN, Palo Alto GlobalProtect) lo gestionan de forma nativa. Para los dispositivos que no admiten el Access-Challenge de RADIUS, Protectimus ofrece el modo Inline. En este modo, los usuarios introducen su contrase\u00f1a y el OTP en un \u00fanico campo usando un separador configurable (por ejemplo, contrase\u00f1a,otp). Este enfoque permite aplicar la MFA incluso en sistemas antiguos que solo admiten un \u00fanico intercambio de autenticaci\u00f3n.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-86abc7e padded e-flex e-con-boxed e-con e-parent\" data-id=\"86abc7e\" data-element_type=\"container\" data-e-type=\"container\" id=\"supported-mfa-methods\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-f0f2e30 e-con-full e-flex e-con e-child\" data-id=\"f0f2e30\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-684bcff elementor-widget elementor-widget-heading\" data-id=\"684bcff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">M\u00e9todos de MFA compatibles con RADIUS<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b52e3d elementor-widget elementor-widget-text-editor\" data-id=\"4b52e3d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Los distintos escenarios de acceso a la red requieren distintos m\u00e9todos de segundo factor. Un cliente de t\u00fanel VPN no tiene interfaz de navegador. Un suplicante Wi-Fi 802.1X corporativo tiene a\u00fan menos. La siguiente tabla asocia los m\u00e9todos con los escenarios.<\/span><\/p><p> <\/p><table><thead><tr><th><b>M\u00e9todo<\/b><\/th><th><b>C\u00f3mo funciona<\/b><\/th><th><b>Ideal para<\/b><\/th><th><b>Notas<\/b><\/th><\/tr><\/thead><tbody><tr><td><a href=\"https:\/\/www.protectimus.com\/es\/token\/smart\/\"><b>App autenticadora (TOTP)<\/b><\/a><\/td><td><span style=\"font-weight: 400;\">C\u00f3digo rotativo de 30 segundos desde una app autenticadora<\/span><\/td><td><span style=\"font-weight: 400;\">VPN y otros servicios compatibles protegidos por RADIUS<\/span><\/td><td><span style=\"font-weight: 400;\">Funciona con pr\u00e1cticamente cualquier cliente RADIUS; no requiere internet tras el registro<\/span><\/td><\/tr><tr><td><a href=\"https:\/\/www.protectimus.com\/es\/tokens\/\"><b>Tokens hardware (TOTP)<\/b><\/a><\/td><td><span style=\"font-weight: 400;\">C\u00f3digo rotativo de 30 segundos desde un dispositivo TOTP f\u00edsico<\/span><\/td><td><span style=\"font-weight: 400;\">Entornos air-gapped, usuarios sin smartphone<\/span><\/td><td><span style=\"font-weight: 400;\">Compatible con Protectimus Two, Slim NFC, Flex, Shark y tokens de terceros compatibles con OATH<\/span><\/td><\/tr><tr><td><a href=\"https:\/\/www.protectimus.com\/es\/token\/sms\/\"><b>SMS OTP<\/b><\/a><\/td><td><span style=\"font-weight: 400;\">C\u00f3digo de 6 d\u00edgitos enviado por SMS<\/span><\/td><td><span style=\"font-weight: 400;\">VPN y otros servicios compatibles protegidos por RADIUS<\/span><\/td><td><span style=\"font-weight: 400;\">Requiere se\u00f1al m\u00f3vil; funciona con el modo Inline<\/span><\/td><\/tr><tr><td><a href=\"https:\/\/www.protectimus.com\/es\/token\/mail\/\"><b>Email OTP<\/b><\/a><\/td><td><span style=\"font-weight: 400;\">C\u00f3digo de 6 d\u00edgitos enviado por email<\/span><\/td><td><span style=\"font-weight: 400;\">VPN y otros servicios compatibles protegidos por RADIUS<\/span><\/td><td><span style=\"font-weight: 400;\">Adecuado donde el SMS no est\u00e1 disponible<\/span><\/td><\/tr><tr><td><a href=\"https:\/\/www.protectimus.com\/es\/token\/bot\/\"><b>Chatbot OTP<\/b><\/a><\/td><td><span style=\"font-weight: 400;\">OTP entregado mediante Telegram, Viber o Facebook Messenger<\/span><\/td><td><span style=\"font-weight: 400;\">VPN y otros servicios compatibles protegidos por RADIUS<\/span><\/td><td><span style=\"font-weight: 400;\">Sin coste de SMS ni dependencia del operador m\u00f3vil<\/span><\/td><\/tr><\/tbody><\/table><p> <\/p><p><b>Espec\u00edficamente para VPN:<\/b><span style=\"font-weight: 400;\"> el TOTP (mediante app o token hardware) y el OTP por chatbot\/SMS\/email funcionan tanto en modo challenge\/response como en modo Inline.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-280411b padded e-flex e-con-boxed e-con e-parent\" data-id=\"280411b\" data-element_type=\"container\" data-e-type=\"container\" id=\"supported-radius-equip\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2bd5d59 e-con-full e-flex e-con e-child\" data-id=\"2bd5d59\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-347cae5 elementor-widget elementor-widget-heading\" data-id=\"347cae5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Clientes RADIUS y equipos de red compatibles<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3977085 elementor-widget elementor-widget-text-editor\" data-id=\"3977085\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus dispone de integraciones documentadas y probadas con el siguiente equipo de red. La <\/span><a href=\"https:\/\/www.protectimus.com\/es\/guides\/radius-2fa\/\"><span style=\"font-weight: 400;\">gu\u00eda completa de integraci\u00f3n RADIUS MFA<\/span><\/a><span style=\"font-weight: 400;\"> incluye la configuraci\u00f3n paso a paso para cada uno.<\/span><\/p><p> <\/p><table><thead><tr><th><p><b>Proveedor<\/b><\/p><\/th><th><p><b>Producto \/ funci\u00f3n<\/b><\/p><\/th><th><p><b>Tipo de acceso<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Cisco<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/cisco-anyconnect\/\"><span style=\"font-weight: 400;\">ASA, FTD, AnyConnect VPN<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cisco<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/cisco-switches-2fa\/\"><span style=\"font-weight: 400;\">Switches Catalyst (inicio de sesi\u00f3n AAA)<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Acceso administrativo<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Juniper<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/juniper-vpn-2fa\/\"><span style=\"font-weight: 400;\">SRX, Pulse Connect Secure<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Fortinet<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/fortigate-vpn-2fa\/\"><span style=\"font-weight: 400;\">FortiGate SSL VPN<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Palo Alto<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/palo-alto-globalprotect-vpn-2fa\/\"><span style=\"font-weight: 400;\">GlobalProtect VPN<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">SonicWall<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/sonicwall-vpn-2fa\/\"><span style=\"font-weight: 400;\">NetExtender, Mobile Connect<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Check Point<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/check-point-vpn-2fa\/\"><span style=\"font-weight: 400;\">Mobile Access blade<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">F5<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/f5-big-ip-apm-vpn-2fa\/\"><span style=\"font-weight: 400;\">APM (Access Policy Manager)<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN \/ proxy de aplicaciones<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Citrix<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/citrix-adc-and-gateway\/\"><span style=\"font-weight: 400;\">ADC (NetScaler)<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN \/ proxy de aplicaciones<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Ubiquiti<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/ubiquiti-unifi-controller-sms-authentication\/\"><span style=\"font-weight: 400;\">UniFi Controller (Guest Portal)<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Wi-Fi de invitados<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Array Networks<\/span><\/p><\/td><td><p><a href=\"https:\/\/www.protectimus.com\/es\/guides\/array-ag-ssl-vpn-2fa\/\"><span style=\"font-weight: 400;\">AG Series SSL VPN<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">VPN<\/span><\/p><\/td><\/tr><\/tbody><\/table><p> <\/p><p><b>Esta lista cubre las implementaciones m\u00e1s comunes. Cualquier dispositivo que env\u00ede solicitudes RADIUS est\u00e1ndar seg\u00fan la RFC 2865 funcionar\u00e1, aunque no figure aqu\u00ed.<\/b><\/p><p><b>Nota: <\/b><span style=\"font-weight: 400;\">algunas implementaciones basadas en RADIUS a\u00fan no est\u00e1n incluidas en nuestras integraciones documentadas. Como Protectimus funciona como un proxy RADIUS basado en est\u00e1ndares, otras arquitecturas RADIUS \u2014incluidas las implementaciones basadas en FreeRADIUS o Microsoft NPS\u2014 tambi\u00e9n pueden ser compatibles. Si est\u00e1 planificando una de estas implementaciones, contacte con nuestro equipo para hablar de su entorno concreto.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a29b829 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a29b829\" data-element_type=\"container\" data-e-type=\"container\" id=\"radius-mfa-for-vpn\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1dc9ec2 e-con-full e-flex e-con e-child\" data-id=\"1dc9ec2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-131348d elementor-widget elementor-widget-heading\" data-id=\"131348d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">RADIUS MFA para VPN<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5266633 elementor-widget elementor-widget-text-editor\" data-id=\"5266633\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"supported-mfa-methods\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La VPN es, con diferencia, la implementaci\u00f3n de RADIUS MFA m\u00e1s habitual, y tambi\u00e9n la m\u00e1s cr\u00edtica desde el punto de vista de la seguridad. Una sesi\u00f3n VPN comprometida otorga a un atacante la misma posici\u00f3n en la red que un empleado remoto leg\u00edtimo, con acceso a recursos compartidos de archivos, aplicaciones web internas, bases de datos y rutas de movimiento lateral.<\/span><\/p><h3><span style=\"font-weight: 400;\">C\u00f3mo funciona la MFA en VPN (sin navegador)<\/span><\/h3><p><span style=\"font-weight: 400;\">Cuando un usuario se conecta mediante Cisco AnyConnect o el cliente SSL VPN de Fortinet, la conexi\u00f3n se inicia a nivel del sistema operativo o de la app cliente. No hay navegador, ni JavaScript, ni URI de redirecci\u00f3n. El cliente VPN env\u00eda las credenciales directamente al NAS, que las reenv\u00eda como un Access-Request de RADIUS.<\/span><\/p><p><span style=\"font-weight: 400;\">Con el soporte de challenge\/response habilitado en el cliente VPN, el flujo funciona exactamente como se describe en la secci\u00f3n de arquitectura: el usuario ve un segundo aviso (&#8220;Introduzca su OTP&#8221;) en la interfaz del cliente VPN tras introducir su contrase\u00f1a. La mayor\u00eda de los clientes VPN modernos representan correctamente este campo, y los usuarios lo encuentran intuitivo.<\/span><\/p><p><span style=\"font-weight: 400;\">Para los clientes VPN antiguos que no admiten el Access-Challenge de RADIUS, Protectimus ofrece el modo Inline. Los usuarios introducen su contrase\u00f1a y el OTP en un \u00fanico campo de autenticaci\u00f3n usando un separador configurado. Esto permite a las organizaciones implementar la MFA sin sustituir su infraestructura VPN existente.<\/span><\/p><p><span style=\"font-weight: 400;\">Aseg\u00farese de que la puerta de enlace VPN pueda alcanzar siempre el servidor RADIUS de Protectimus (UDP 1812\/1813 si se usa el registro contable), independientemente de la configuraci\u00f3n de enrutamiento de la VPN.<\/span><\/p><p><span style=\"font-weight: 400;\">Consulte la gu\u00eda completa de integraci\u00f3n RADIUS MFA y <\/span><a href=\"https:\/\/www.protectimus.com\/es\/es-mfa-for-cisco-anyconnect\/\"><span style=\"font-weight: 400;\">MFA for Cisco AnyConnect VPN <\/span><\/a><span style=\"font-weight: 400;\">para conocer los pasos de configuraci\u00f3n espec\u00edficos de cada proveedor.<\/span><\/p><p>Para obtener una descripci\u00f3n general completa de la implementaci\u00f3n de MFA en Cisco, Fortinet, Palo Alto, SonicWall, OpenVPN y otras puertas de enlace VPN, consulte la <a href=\"https:\/\/www.protectimus.com\/es\/mfa-for-vpn\/\">soluci\u00f3n Protectimus MFA para VPN<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-16797b4 padded e-flex e-con-boxed e-con e-parent\" data-id=\"16797b4\" data-element_type=\"container\" data-e-type=\"container\" id=\"radius-mfa-for-wlan-access\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-bb86bc5 e-con-full e-flex e-con e-child\" data-id=\"bb86bc5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-891beb3 elementor-widget elementor-widget-heading\" data-id=\"891beb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">RADIUS MFA para el acceso a redes inal\u00e1mbricas<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7f6098 elementor-widget elementor-widget-text-editor\" data-id=\"d7f6098\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Aunque la VPN es la implementaci\u00f3n de RADIUS MFA m\u00e1s habitual, las organizaciones tambi\u00e9n usan RADIUS para proteger el acceso a redes inal\u00e1mbricas. El flujo exacto de autenticaci\u00f3n depende de la infraestructura inal\u00e1mbrica y del m\u00e9todo de autenticaci\u00f3n en uso.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Protectimus admite escenarios de acceso inal\u00e1mbrico que se integran con la <\/span><a href=\"https:\/\/www.protectimus.com\/es\/wifi-sms-authentication\/\"><span style=\"font-weight: 400;\">RADIUS-based authentication<\/span><\/a><span style=\"font-weight: 400;\">, incluidas implementaciones de Wi-Fi de invitados como el Ubiquiti UniFi Guest Portal. En estos entornos, los usuarios se autentican mediante una contrase\u00f1a de un solo uso entregada por SMS, chatbot, email, o un TOTP generado por una app autenticadora o un token hardware, seg\u00fan la implementaci\u00f3n.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Para entornos de Wi-Fi de invitados, Protectimus puede desplegarse con el servicio en la nube de Protectimus o con la Protectimus On-Premise Platform. Las solicitudes de autenticaci\u00f3n se validan a trav\u00e9s de la plataforma de Protectimus antes de conceder el acceso a la red, mientras los administradores conservan capacidades centralizadas de registro y gesti\u00f3n de usuarios.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Al planificar la MFA para redes inal\u00e1mbricas empresariales, verifique que su infraestructura inal\u00e1mbrica y su flujo de autenticaci\u00f3n admiten el m\u00e9todo de autenticaci\u00f3n RADIUS requerido. Las capacidades de autenticaci\u00f3n pueden variar seg\u00fan el controlador inal\u00e1mbrico, la puerta de enlace de acceso o la implementaci\u00f3n del portal cautivo.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dd147b2 padded e-flex e-con-boxed e-con e-parent\" data-id=\"dd147b2\" data-element_type=\"container\" data-e-type=\"container\" id=\"deployment-opt\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-c9b7b25 e-con-full e-flex e-con e-child\" data-id=\"c9b7b25\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fad9de1 elementor-widget elementor-widget-heading\" data-id=\"fad9de1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Opciones de implementaci\u00f3n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-78865c0 elementor-widget elementor-widget-text-editor\" data-id=\"78865c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"font-weight: 400;\">RADIUS MFA en la nube (SaaS)<\/span><\/h3><p><span style=\"font-weight: 400;\">El servidor RADIUS de Protectimus se instala dentro de su red y se configura para comunicarse con el servicio en la nube de Protectimus. Sus dispositivos de red env\u00edan las solicitudes de autenticaci\u00f3n RADIUS al servidor RADIUS local de Protectimus, que valida las credenciales principales del usuario contra su Active Directory o LDAP y verifica el segundo factor a trav\u00e9s del servicio en la nube de Protectimus. No se requiere ninguna plataforma de MFA on-premises, lo que hace que esta implementaci\u00f3n sea adecuada para las organizaciones que desean una implementaci\u00f3n r\u00e1pida y una infraestructura m\u00ednima.<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">Servidor RADIUS MFA on-premises<\/span><\/h3><p><span style=\"font-weight: 400;\">El servidor RADIUS de Protectimus y la Protectimus On-Premise Platform se instalan en servidores est\u00e1ndar Windows Server o Linux dentro de su red. El servidor RADIUS valida las credenciales principales contra Active Directory o LDAP y verifica el segundo factor usando la plataforma local de Protectimus. Todas las solicitudes de autenticaci\u00f3n permanecen dentro de su infraestructura, lo que hace que esta implementaci\u00f3n sea adecuada para organizaciones con requisitos de residencia de datos, entornos air-gapped o pol\u00edticas de seguridad internas que proh\u00edben los servicios de autenticaci\u00f3n en la nube.<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">Configuraci\u00f3n de alta disponibilidad<\/span><\/h3><p><span style=\"font-weight: 400;\">En ambos modos de implementaci\u00f3n, Protectimus admite configuraciones de alta disponibilidad. Las organizaciones pueden desplegar instancias primarias y secundarias del servidor RADIUS de Protectimus. Los dispositivos de red pueden configurarse con ambas IP de servidor usando el failover RADIUS est\u00e1ndar (el servidor secundario se usa si el primario no responde dentro del per\u00edodo de tiempo de espera configurado). La mayor\u00eda de los firewalls empresariales, puertas de enlace VPN y clientes RADIUS admiten esto de forma nativa.<\/span><\/p><p><span style=\"font-weight: 400;\">En las implementaciones en la nube, las instancias redundantes del servidor RADIUS de Protectimus se conectan al servicio en la nube de Protectimus. En las implementaciones on-premises, la alta disponibilidad tambi\u00e9n puede extenderse a la propia Plataforma Protectimus despleg\u00e1ndola como un cl\u00faster tras un balanceador de carga gestionado por el cliente. Las organizaciones tambi\u00e9n pueden desplegar componentes en ubicaciones separadas para reducir a\u00fan m\u00e1s el riesgo de interrupci\u00f3n del servicio.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2442ac padded e-flex e-con-boxed e-con e-parent\" data-id=\"a2442ac\" data-element_type=\"container\" data-e-type=\"container\" id=\"system-requirements\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-d2891c1 e-con-full e-flex e-con e-child\" data-id=\"d2891c1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f2847f8 elementor-widget elementor-widget-heading\" data-id=\"f2847f8\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"howtosetup\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Requisitos del sistema e integraci\u00f3n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-32a2622 elementor-widget elementor-widget-text-editor\" data-id=\"32a2622\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table><thead><tr><th><p><b>Componente<\/b><\/p><\/th><th><p><b>Requisito<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><b>Opciones de implementaci\u00f3n<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Windows, Linux, Docker<\/span><\/p><\/td><\/tr><tr><td><p><b>Puertos RADIUS<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">UDP 1812 (autenticaci\u00f3n), UDP 1813 (registro contable)<\/span><\/p><\/td><\/tr><tr><td><p><b>Protocolo IP<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Compatible con IPv4 e IPv6<\/span><\/p><\/td><\/tr><tr><td><p><b>Integraci\u00f3n con directorios<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Directorios Active Directory y LDAP<\/span><\/p><\/td><\/tr><tr><td><p><b>Dispositivos de red<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cualquier cliente RADIUS compatible con RFC 2865<\/span><\/p><\/td><\/tr><tr><td><p><b>Java<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Java es necesario para las instalaciones en Windows. Si Java no est\u00e1 instalado, el instalador puede instalarlo autom\u00e1ticamente. Consulte la documentaci\u00f3n actual de Protectimus para conocer las versiones compatibles.<\/span><\/p><\/td><\/tr><tr><td><p><b>Reglas de firewall<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">UDP 1812 abierto entre los clientes RADIUS y el servidor RADIUS de Protectimus; acceso LDAP\/LDAPS (389\/636) desde el servidor RADIUS de Protectimus hasta Active Directory o LDAP, si se usa para la autenticaci\u00f3n principal.<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-41f9125 padded e-flex e-con-boxed e-con e-parent\" data-id=\"41f9125\" data-element_type=\"container\" data-e-type=\"container\" id=\"radius-setup\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-58d168e e-con-full e-flex e-con e-child\" data-id=\"58d168e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f023dfa elementor-widget elementor-widget-heading\" data-id=\"f023dfa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Paso a paso: c\u00f3mo configurar RADIUS MFA en 5 pasos<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d798bf elementor-widget elementor-widget-text-editor\" data-id=\"9d798bf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Paso 1 \u2014 implemente el servidor RADIUS de Protectimus.<\/b><span style=\"font-weight: 400;\">Elija la implementaci\u00f3n en la nube o on-premises. Para la nube, cree una cuenta en service.protectimus.com, active el acceso a la API e instale el servidor RADIUS de Protectimus dentro de su red. Para on-premises, descargue el paquete instalador, ejec\u00fatelo en su servidor Windows o Linux de destino, e instale tanto el servidor RADIUS de Protectimus como la Protectimus On-Premise Platform.<\/span><\/p>\n<p><b>Paso 2 \u2014 configure su conexi\u00f3n AD\/LDAP.<\/b><span style=\"font-weight: 400;\">In the Protectimus RADIUS Server configuration file, add your domain controller address, bind account, search base, and authentication provider settings. Test the connection to confirm that the Protectimus RADIUS Server can communicate with your directory service.<\/span><\/p>\n<p><b>Paso 3 \u2014 a\u00f1ada su dispositivo de red como cliente RADIUS. <\/b><span style=\"font-weight: 400;\">En la configuraci\u00f3n del servidor RADIUS de Protectimus, registre la direcci\u00f3n IP y el secreto compartido de cada dispositivo NAS, como su puerta de enlace VPN, firewall u otro dispositivo de red compatible. Este es el mismo secreto compartido que configurar\u00e1 en el lado del dispositivo.<\/span><\/p>\n<p><b>Paso 4 \u2014 dirija el dispositivo de red hacia Protectimus. <\/b><span style=\"font-weight: 400;\">En su Cisco ASA, Fortinet, Palo Alto u otro dispositivo compatible, cambie la IP del servidor RADIUS al servidor RADIUS de Protectimus. Configure el secreto compartido para que coincida con el que configur\u00f3 en el Paso 3 y configure el puerto UDP 1812 para la autenticaci\u00f3n RADIUS.<\/span><\/p>\n<p><b>Paso 5 \u2014 registre a los usuarios y pruebe. <\/b><span style=\"font-weight: 400;\">Registre un grupo piloto de usuarios, ya sea envi\u00e1ndoles un enlace de autorregistro o mediante importaci\u00f3n masiva a trav\u00e9s de un grupo de AD. P\u00eddales que escaneen un c\u00f3digo QR en su app autenticadora o as\u00edgneles tokens hardware. Pruebe el flujo completo de autenticaci\u00f3n usando su servicio protegido por RADIUS: introduzca las credenciales, complete el desaf\u00edo de OTP y confirme que se concede el acceso tras un c\u00f3digo v\u00e1lido.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Para el recorrido t\u00e9cnico completo con capturas de pantalla espec\u00edficas de cada proveedor, consulte la <\/span><a href=\"https:\/\/www.protectimus.com\/es\/guides\/radius-2fa\/\"><span style=\"font-weight: 400;\">gu\u00eda completa de integraci\u00f3n RADIUS MFA<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p> <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-70d012a padded e-flex e-con-boxed e-con e-parent\" data-id=\"70d012a\" data-element_type=\"container\" data-e-type=\"container\" id=\"radius-mfa-compliance\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-af82edd e-con-full e-flex e-con e-child\" data-id=\"af82edd\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a4316cb elementor-widget elementor-widget-heading\" data-id=\"a4316cb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Cumplimiento: c\u00f3mo RADIUS MFA satisface los requisitos normativos<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-801b04d elementor-widget elementor-widget-text-editor\" data-id=\"801b04d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><span style=\"font-weight: 400;\">NIST SP 800-63B (AAL2)<\/span><\/h3><p><span style=\"font-weight: 400;\">Las directrices de identidad digital de NIST definen tres Niveles de Garant\u00eda de Autenticador. AAL2 exige dos factores de autenticaci\u00f3n distintos para el acceso a sistemas sensibles. La MFA de RADIUS con TOTP o tokens hardware satisface directamente los requisitos de AAL2: la contrase\u00f1a es el secreto memorizado (algo que usted sabe), y el c\u00f3digo TOTP lo genera un autenticador vinculado (algo que usted tiene).<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">PCI DSS v4.0 \u2014 Requisito 8.4<\/span><\/h3><p><span style=\"font-weight: 400;\">El Requisito 8.4.2 de PCI DSS v4.0 exige MFA para todo acceso al entorno de datos de titulares de tarjetas, para cualquier usuario, ya se conecte de forma remota o desde dentro de la red. El Requisito 8.4.3 se centra espec\u00edficamente en el acceso remoto: se exige MFA para todo acceso remoto a la red hacia el CDE que se origine fuera de la red de la organizaci\u00f3n, cubriendo por igual a empleados, contratistas y proveedores externos. RADIUS MFA ayuda a las organizaciones a satisfacer ambos requisitos aplicando la MFA para VPN y otros accesos protegidos por RADIUS a sistemas dentro del entorno de datos de titulares de tarjetas.<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">HIPAA \u2014 controles de acceso (45 CFR \u00a7 164.312)<\/span><\/h3><p><span style=\"font-weight: 400;\">La salvaguarda t\u00e9cnica de HIPAA sobre el control de acceso exige a las entidades cubiertas implementar procedimientos que concedan acceso a la ePHI \u00fanicamente a personas autorizadas. RADIUS MFA aborda esto directamente a\u00f1adiendo un segundo paso de verificaci\u00f3n al acceso VPN y Wi-Fi, las dos v\u00edas m\u00e1s habitualmente usadas para el acceso remoto a sistemas cl\u00ednicos.<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">Directiva NIS2 (UE) \u2014 art\u00edculo 21<\/span><\/h3><p><span style=\"font-weight: 400;\">NIS2 exige a las entidades esenciales e importantes implementar soluciones de autenticaci\u00f3n multifactor o continua para el acceso a los sistemas de red e informaci\u00f3n. RADIUS MFA satisface este requisito para los escenarios de acceso remoto, expl\u00edcitamente se\u00f1alados en la gu\u00eda de implementaci\u00f3n de ENISA.<\/span><\/p><p> <\/p><h3><span style=\"font-weight: 400;\">ISO\/IEC 27001:2022 \u2014 Anexo A 8.5<\/span><\/h3><p><span style=\"font-weight: 400;\">El control de ISO 27001 sobre autenticaci\u00f3n segura recomienda expl\u00edcitamente la MFA para escenarios de acceso de alto riesgo, incluidos el acceso remoto y las cuentas privilegiadas. RADIUS MFA ayuda a las organizaciones a implementar este control para VPN y otros servicios protegidos por RADIUS.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a9cb282 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a9cb282\" data-element_type=\"container\" data-e-type=\"container\" id=\"radius-mfa-faq\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7659ffd elementor-widget elementor-widget-heading\" data-id=\"7659ffd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Preguntas frecuentes<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dc81e4c e-con-full padded e-flex e-con e-child\" data-id=\"dc81e4c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-fb2596d e-con-full faq-container e-flex e-con e-child\" data-id=\"fb2596d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-412fa06 plus-right elementor-widget elementor-widget-n-accordion\" data-id=\"412fa06\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;all_collapsed&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6830\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6830\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfAdmite Protectimus el Access-Challenge de RADIUS para la introducci\u00f3n interactiva de OTP? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6830\" class=\"elementor-element elementor-element-ea1991a e-con-full e-flex e-con e-child\" data-id=\"ea1991a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8bad61c elementor-widget elementor-widget-text-editor\" data-id=\"8bad61c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed. Protectimus usa el Access-Challenge de RADIUS de forma nativa para los avisos interactivos de OTP. Cuando el dispositivo NAS admite challenge\/response (como hacen la mayor\u00eda de los clientes VPN modernos), los usuarios ven un segundo campo de entrada para su OTP tras introducir su contrase\u00f1a. Para los dispositivos que no admiten challenge\/response, el modo Inline est\u00e1 disponible como alternativa.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6831\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6831\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfPuedo usar la MFA RADIUS de Protectimus sin sustituir mi servidor RADIUS o NPS existente? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6831\" class=\"elementor-element elementor-element-b2bdc68 e-con-full e-flex e-con e-child\" data-id=\"b2bdc68\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f30747e elementor-widget elementor-widget-text-editor\" data-id=\"f30747e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed, y este es el modelo de implementaci\u00f3n m\u00e1s habitual. Protectimus funciona como un proxy RADIUS situado por delante de su servidor de autenticaci\u00f3n existente. Sus dispositivos NAS apuntan a Protectimus; Protectimus gestiona la aplicaci\u00f3n de la MFA y luego reenv\u00eda la solicitud validada. Sus pol\u00edticas de autenticaci\u00f3n, enrutamiento y configuraci\u00f3n de registro contable existentes permanecen sin cambios.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6832\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6832\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfQu\u00e9 puerto de autenticaci\u00f3n RADIUS usa Protectimus? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6832\" class=\"elementor-element elementor-element-0787040 e-con-full e-flex e-con e-child\" data-id=\"0787040\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9eb7aff elementor-widget elementor-widget-text-editor\" data-id=\"9eb7aff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Protectimus usa el puerto de autenticaci\u00f3n RADIUS est\u00e1ndar: UDP 1812. El registro contable (si se necesita) usa UDP 1813. Ambos son configurables.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6833\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6833\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfC\u00f3mo funciona la MFA en VPN cuando no hay interfaz de navegador? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6833\" class=\"elementor-element elementor-element-b3373c0 e-con-full e-flex e-con e-child\" data-id=\"b3373c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ef49d2 elementor-widget elementor-widget-text-editor\" data-id=\"6ef49d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Se admiten dos modos. En el modo challenge\/response, el cliente VPN muestra un segundo aviso tras aceptar la contrase\u00f1a; el usuario introduce su OTP en ese campo. En el modo Inline, el usuario introduce su contrase\u00f1a y el OTP juntos en un \u00fanico campo usando un separador configurado. No se requiere navegador en ning\u00fan caso; todo el flujo ocurre dentro de la interfaz de autenticaci\u00f3n nativa del cliente.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6834\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6834\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfAdmite RADIUS de Protectimus la alta disponibilidad y el failover? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6834\" class=\"elementor-element elementor-element-3e2c10e e-con-full e-flex e-con e-child\" data-id=\"3e2c10e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1ee304 elementor-widget elementor-widget-text-editor\" data-id=\"e1ee304\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed. Puede desplegar varias instancias del servidor RADIUS de Protectimus y configurar sus dispositivos NAS con objetivos RADIUS primario y secundario. Si el servidor primario no responde dentro del tiempo de espera de RADIUS, el NAS reintenta autom\u00e1ticamente con el secundario. En las implementaciones on-premises, la alta disponibilidad tambi\u00e9n puede extenderse a la plataforma de Protectimus despleg\u00e1ndola como un cl\u00faster. Los dispositivos de red cambian autom\u00e1ticamente al servidor secundario cuando el primario deja de estar disponible, ayudando a mantener la disponibilidad de la autenticaci\u00f3n.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6835\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6835\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfPuedo integrar RADIUS de Protectimus con Active Directory? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6835\" class=\"elementor-element elementor-element-67bff32 e-con-full e-flex e-con e-child\" data-id=\"67bff32\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ed5da62 elementor-widget elementor-widget-text-editor\" data-id=\"ed5da62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed, y esta es la configuraci\u00f3n predeterminada para la mayor\u00eda de las implementaciones empresariales. Protectimus se conecta a su AD mediante LDAP o LDAPS (puerto 389\/636) y reenv\u00eda la validaci\u00f3n de contrase\u00f1a al controlador de dominio. Se admiten pol\u00edticas basadas en grupos: puede exigir MFA para algunos grupos de AD y eximir a otros, o asignar m\u00e9todos de MFA distintos seg\u00fan el grupo.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"\\u00bfAdmite Protectimus el Access-Challenge de RADIUS para la introducci\\u00f3n interactiva de OTP?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed. Protectimus usa el Access-Challenge de RADIUS de forma nativa para los avisos interactivos de OTP. Cuando el dispositivo NAS admite challenge\\\/response (como hacen la mayor\\u00eda de los clientes VPN modernos), los usuarios ven un segundo campo de entrada para su OTP tras introducir su contrase\\u00f1a. Para los dispositivos que no admiten challenge\\\/response, el modo Inline est\\u00e1 disponible como alternativa.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfPuedo usar la MFA RADIUS de Protectimus sin sustituir mi servidor RADIUS o NPS existente?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed, y este es el modelo de implementaci\\u00f3n m\\u00e1s habitual. Protectimus funciona como un proxy RADIUS situado por delante de su servidor de autenticaci\\u00f3n existente. Sus dispositivos NAS apuntan a Protectimus; Protectimus gestiona la aplicaci\\u00f3n de la MFA y luego reenv\\u00eda la solicitud validada. Sus pol\\u00edticas de autenticaci\\u00f3n, enrutamiento y configuraci\\u00f3n de registro contable existentes permanecen sin cambios.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfQu\\u00e9 puerto de autenticaci\\u00f3n RADIUS usa Protectimus?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Protectimus usa el puerto de autenticaci\\u00f3n RADIUS est\\u00e1ndar: UDP 1812. El registro contable (si se necesita) usa UDP 1813. Ambos son configurables.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfC\\u00f3mo funciona la MFA en VPN cuando no hay interfaz de navegador?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Se admiten dos modos. En el modo challenge\\\/response, el cliente VPN muestra un segundo aviso tras aceptar la contrase\\u00f1a; el usuario introduce su OTP en ese campo. En el modo Inline, el usuario introduce su contrase\\u00f1a y el OTP juntos en un \\u00fanico campo usando un separador configurado. No se requiere navegador en ning\\u00fan caso; todo el flujo ocurre dentro de la interfaz de autenticaci\\u00f3n nativa del cliente.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfAdmite RADIUS de Protectimus la alta disponibilidad y el failover?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed. Puede desplegar varias instancias del servidor RADIUS de Protectimus y configurar sus dispositivos NAS con objetivos RADIUS primario y secundario. Si el servidor primario no responde dentro del tiempo de espera de RADIUS, el NAS reintenta autom\\u00e1ticamente con el secundario. En las implementaciones on-premises, la alta disponibilidad tambi\\u00e9n puede extenderse a la plataforma de Protectimus despleg\\u00e1ndola como un cl\\u00faster. Los dispositivos de red cambian autom\\u00e1ticamente al servidor secundario cuando el primario deja de estar disponible, ayudando a mantener la disponibilidad de la autenticaci\\u00f3n.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfPuedo integrar RADIUS de Protectimus con Active Directory?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed, y esta es la configuraci\\u00f3n predeterminada para la mayor\\u00eda de las implementaciones empresariales. Protectimus se conecta a su AD mediante LDAP o LDAPS (puerto 389\\\/636) y reenv\\u00eda la validaci\\u00f3n de contrase\\u00f1a al controlador de dominio. Se admiten pol\\u00edticas basadas en grupos: puede exigir MFA para algunos grupos de AD y eximir a otros, o asignar m\\u00e9todos de MFA distintos seg\\u00fan el grupo.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7534fb4 elementor-widget elementor-widget-html\" data-id=\"7534fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"HowTo\",\r\n  \"name\": \"How to Set Up RADIUS MFA in 5 Steps\",\r\n  \"description\": \"Add multi-factor authentication to any RADIUS-compatible VPN gateway, firewall, or network device using the Protectimus RADIUS Server, with cloud or on-premise deployment.\",\r\n  \"totalTime\": \"PT1H\",\r\n  \"tool\": [\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus RADIUS Server\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus Cloud Service or On-Premise Platform\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"RADIUS-compatible network device (VPN gateway, firewall, Wi-Fi controller)\"\r\n    }\r\n  ],\r\n  \"step\": [\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 1,\r\n      \"name\": \"Deploy the Protectimus RADIUS Server\",\r\n      \"text\": \"Choose Cloud or On-Premise deployment. For Cloud, create an account at service.protectimus.com, activate API access, and install the Protectimus RADIUS Server inside your network. For On-Premise, download the installer package, run it on your target Windows or Linux server, and install both the Protectimus RADIUS Server and the Protectimus On-Premise Platform.\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 2,\r\n      \"name\": \"Configure your AD\/LDAP connection\",\r\n      \"text\": \"In the Protectimus RADIUS Server configuration file, add your domain controller address, bind account, search base, and authentication provider settings. Test the connection to confirm that the Protectimus RADIUS Server can communicate with your directory service.\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 3,\r\n      \"name\": \"Add your network device as a RADIUS client\",\r\n      \"text\": \"In the Protectimus RADIUS Server configuration, register the IP address and shared secret for each NAS device, such as your VPN gateway, firewall, or other supported network device. This is the same shared secret you'll configure on the device side.\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 4,\r\n      \"name\": \"Point the network device to Protectimus\",\r\n      \"text\": \"On your Cisco ASA, Fortinet, Palo Alto, or other supported device, change the RADIUS server IP to the Protectimus RADIUS Server. Set the shared secret to match what you configured in Step 3 and configure UDP port 1812 for RADIUS authentication.\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 5,\r\n      \"name\": \"Enroll users and test\",\r\n      \"text\": \"Enroll a pilot group of users \u2014 either by sending them a self-enrollment link or by bulk-importing via an AD group. Have them scan a QR code in their authenticator app or assign hardware tokens. Test the complete authentication flow using your RADIUS-protected service: enter credentials, complete the OTP challenge, and confirm that access is granted after a valid code.\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fe2c5b0 padded e-flex e-con-boxed e-con e-parent\" data-id=\"fe2c5b0\" data-element_type=\"container\" data-e-type=\"container\" id=\"get-protected\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e4ec716 e-con-full e-flex e-con e-child\" data-id=\"e4ec716\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-35746bf e-con-full e-flex e-con e-child\" data-id=\"35746bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-489bd70 e-con-full e-flex e-con e-child\" data-id=\"489bd70\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10cf0aa elementor-widget elementor-widget-heading\" data-id=\"10cf0aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Empiece a proteger el acceso a su red hoy mismo<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c0eeb4 elementor-widget elementor-widget-text-editor\" data-id=\"6c0eeb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Cada endpoint VPN, cada red Wi-Fi corporativa y cada servicio protegido por RADIUS es un punto de entrada potencial. RADIUS MFA cierra la brecha de la autenticaci\u00f3n basada \u00fanicamente en credenciales sin requerir cambios en su infraestructura de red existente.<\/p><ul><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/platform\/\"><span style=\"font-weight: 400;\">Implementar on-premises \u2192 Protectimus On-Prem MFA Platform<\/span><\/a><\/li><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/guides\/saas-service\/\"><span style=\"font-weight: 400;\">Usar el servicio en la nube \u2192 Gu\u00eda de configuraci\u00f3n de Protectimus SaaS<\/span><\/a><\/li><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/guides\/radius-2fa\/\"><span style=\"font-weight: 400;\">Leer la gu\u00eda t\u00e9cnica \u2192 Gu\u00eda completa de integraci\u00f3n RADIUS MFA<\/span><\/a><\/li><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/tokens\/\"><span style=\"font-weight: 400;\">Tokens hardware para RADIUS MFA \u2192 Tokens de Protectimus<\/span><\/a><\/li><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/es-mfa-for-cisco-anyconnect\/\"><span style=\"font-weight: 400;\">MFA para Active Directory \u2192 Gu\u00eda de MFA agentless para AD<\/span><\/a><\/li><li style=\"font-weight: 400; text-align: left;\" aria-level=\"1\"><a href=\"https:\/\/www.protectimus.com\/es\/winlogon\/\"><span style=\"font-weight: 400;\">MFA para el inicio de sesi\u00f3n de Windows y RDP \u2192 Componente Winlogon<\/span><\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a3f81ec e-con-full contact-us-bg e-flex e-con e-child\" data-id=\"a3f81ec\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fb3d121 elementor-widget elementor-widget-shortcode\" data-id=\"fb3d121\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"container\" data-elementor-id=\"17554\" class=\"elementor elementor-17554 elementor-3585\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3a82e0d1 e-con-full e-flex e-con e-child\" data-id=\"3a82e0d1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b4de036 elementor-widget elementor-widget-image\" data-id=\"b4de036\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"370\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/05\/contact-seal.svg\" class=\"attachment-full size-full wp-image-17583\" alt=\"Send Us A Message icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1bc85d61 elementor-widget elementor-widget-heading\" data-id=\"1bc85d61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Env\u00edenos un mensaje<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cf09046 elementor-widget elementor-widget-shortcode\" data-id=\"cf09046\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f17553-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"17553\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/es\/wp-json\/wp\/v2\/pages\/18589#wpcf7-f17553-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"17553\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.2\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f17553-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/>\n<\/fieldset>\n<div class=\"protectimus-form\">\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"uname\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Nombre\" value=\"\" type=\"text\" name=\"uname\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Correo electr\u00f3nico\" value=\"\" type=\"email\" name=\"email\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"subject\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Asunto\" value=\"\" type=\"text\" name=\"subject\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"message\"><textarea cols=\"40\" rows=\"1\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Mensaje\" name=\"message\"><\/textarea><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col mb-2\">\n        <input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Enviar\" \/>\n    <\/div>\n<\/div>\n\n<\/div><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-311ad2c e-grid e-con-full equal-height equal-height-mob e-con e-child\" data-id=\"311ad2c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<a target=\"_blank\" target=\"_blank\" class=\"elementor-element elementor-element-feb2bbc e-con-full four-link e-flex e-con e-child\" data-id=\"feb2bbc\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/service.protectimus.com\/en\/register\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f27e21b eq-height elementor-widget elementor-widget-heading\" data-id=\"f27e21b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Iniciar prueba gratuita<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-76c9612 elementor-widget elementor-widget-image\" data-id=\"76c9612\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-4ccade8 e-con-full four-link e-flex e-con e-child\" data-id=\"4ccade8\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/www.protectimus.com\/es\/contact-us\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-45ea78d eq-height elementor-widget elementor-widget-heading\" data-id=\"45ea78d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Contact sales<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e65f9a1 elementor-widget elementor-widget-image\" data-id=\"e65f9a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-c9d4aa4 e-con-full four-link e-flex e-con e-child\" data-id=\"c9d4aa4\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/es\/pricing\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b9e4eb6 eq-height elementor-widget elementor-widget-heading\" data-id=\"b9e4eb6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Detalles de precios<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-120f334 elementor-widget elementor-widget-image\" data-id=\"120f334\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-e82cb51 e-con-full four-link e-flex e-con e-child\" data-id=\"e82cb51\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/ru\/guides\/saas-service\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d33e100 eq-height elementor-widget elementor-widget-heading\" data-id=\"d33e100\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Gu\u00edas de integraci\u00f3n<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3de24d6 elementor-widget elementor-widget-image\" data-id=\"3de24d6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red RADIUS \u2014el protocolo que gestiona silenciosamente la autenticaci\u00f3n de la mayor\u00eda de las VPN corporativas, redes Wi-Fi e infraestructuras de red\u2014 se dise\u00f1\u00f3 en otra \u00e9poca. Cumple su funci\u00f3n con fiabilidad: un dispositivo de red env\u00eda credenciales a un servidor RADIUS, el servidor [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"class_list":["post-18589","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"google-site-verification\" content=\"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.protectimus.com\/es\/radius-authentication\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"PROTECTIMUS\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus\" \/>\n\t\t<meta property=\"og:description\" content=\"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.protectimus.com\/es\/radius-authentication\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-02T11:39:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-27T19:08:20+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/protectimus\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@Protectimus\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@Protectimus\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"accounts@vipertop.com\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"23 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#listItem\",\"name\":\"Autenticaci\\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#listItem\",\"position\":2,\"name\":\"Autenticaci\\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\",\"name\":\"Protectimus Ltd\",\"description\":\"Protectimus Ltd is a multi-factor authentication provider offering cloud and on-premise MFA software, hardware OTP tokens, authenticator applications, and ready-to-use integrations for enterprise infrastructure.\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"email\":\"sales@protectimus.com\",\"telephone\":\"+17867966664\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/logo-icon.svg\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#organizationLogo\",\"width\":72,\"height\":51,\"caption\":\"Protectimus logo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/protectimus\\\/\",\"https:\\\/\\\/x.com\\\/Protectimus\",\"https:\\\/\\\/www.youtube.com\\\/@ProtectimusSolutions\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/protectimus-solution-ltd\\\/\",\"https:\\\/\\\/github.com\\\/protectimus\",\"https:\\\/\\\/www.g2.com\\\/products\\\/protectimus\\\/reviews\",\"https:\\\/\\\/www.capterra.com\\\/p\\\/182993\\\/Protectimus\\\/\",\"https:\\\/\\\/www.gartner.com\\\/reviews\\\/product\\\/protectimus\",\"https:\\\/\\\/sourceforge.net\\\/software\\\/product\\\/Protectimus\\\/\",\"https:\\\/\\\/www.getapp.com\\\/security-software\\\/a\\\/protectimus\\\/\",\"https:\\\/\\\/www.softwareadvice.com\\\/product\\\/462406-Protectimus\\\/\",\"https:\\\/\\\/www.trustradius.com\\\/products\\\/protectimus\\\/reviews\",\"https:\\\/\\\/www.trustpilot.com\\\/review\\\/protectimus.com\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#webpage\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/\",\"name\":\"Autenticaci\\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus\",\"description\":\"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.\",\"inLanguage\":\"es-ES\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/radius-authentication\\\/#breadcrumblist\"},\"datePublished\":\"2026-07-02T11:39:03+00:00\",\"dateModified\":\"2026-08-27T19:08:20+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"name\":\"PROTECTIMUS\",\"inLanguage\":\"es-ES\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus<\/title>\n\n","aioseo_head_json":{"title":"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus","description":"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.","canonical_url":"https:\/\/www.protectimus.com\/es\/radius-authentication\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","position":1,"name":"Home","item":"https:\/\/www.protectimus.com\/es\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#listItem","name":"Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#listItem","position":2,"name":"Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red","previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/www.protectimus.com\/es\/#organization","name":"Protectimus Ltd","description":"Protectimus Ltd is a multi-factor authentication provider offering cloud and on-premise MFA software, hardware OTP tokens, authenticator applications, and ready-to-use integrations for enterprise infrastructure.","url":"https:\/\/www.protectimus.com\/es\/","email":"sales@protectimus.com","telephone":"+17867966664","logo":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/logo-icon.svg","@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#organizationLogo","width":72,"height":51,"caption":"Protectimus logo"},"image":{"@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/protectimus\/","https:\/\/x.com\/Protectimus","https:\/\/www.youtube.com\/@ProtectimusSolutions","https:\/\/www.linkedin.com\/company\/protectimus-solution-ltd\/","https:\/\/github.com\/protectimus","https:\/\/www.g2.com\/products\/protectimus\/reviews","https:\/\/www.capterra.com\/p\/182993\/Protectimus\/","https:\/\/www.gartner.com\/reviews\/product\/protectimus","https:\/\/sourceforge.net\/software\/product\/Protectimus\/","https:\/\/www.getapp.com\/security-software\/a\/protectimus\/","https:\/\/www.softwareadvice.com\/product\/462406-Protectimus\/","https:\/\/www.trustradius.com\/products\/protectimus\/reviews","https:\/\/www.trustpilot.com\/review\/protectimus.com"]},{"@type":"WebPage","@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#webpage","url":"https:\/\/www.protectimus.com\/es\/radius-authentication\/","name":"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus","description":"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.","inLanguage":"es-ES","isPartOf":{"@id":"https:\/\/www.protectimus.com\/es\/#website"},"breadcrumb":{"@id":"https:\/\/www.protectimus.com\/es\/radius-authentication\/#breadcrumblist"},"datePublished":"2026-07-02T11:39:03+00:00","dateModified":"2026-08-27T19:08:20+00:00"},{"@type":"WebSite","@id":"https:\/\/www.protectimus.com\/es\/#website","url":"https:\/\/www.protectimus.com\/es\/","name":"PROTECTIMUS","inLanguage":"es-ES","publisher":{"@id":"https:\/\/www.protectimus.com\/es\/#organization"}}]},"og:locale":"es_ES","og:site_name":"PROTECTIMUS","og:type":"article","og:title":"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus","og:description":"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.","og:url":"https:\/\/www.protectimus.com\/es\/radius-authentication\/","og:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","og:image:secure_url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","article:published_time":"2026-07-02T11:39:03+00:00","article:modified_time":"2026-08-27T19:08:20+00:00","article:publisher":"https:\/\/www.facebook.com\/protectimus\/","twitter:card":"summary_large_image","twitter:site":"@Protectimus","twitter:title":"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus","twitter:description":"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.","twitter:creator":"@Protectimus","twitter:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","twitter:label1":"Written by","twitter:data1":"accounts@vipertop.com","twitter:label2":"Est. reading time","twitter:data2":"23 minutes"},"aioseo_meta_data":{"post_id":"18589","title":"Autenticaci\u00f3n RADIUS con MFA para VPN y Wi-Fi | Protectimus","description":"Acceso seguro a VPN, Wi-Fi y red con RADIUS MFA. El proxy Protectimus agrega 2FA sin cambios de infraestructura. On-premise o en la nube. Comienza tu prueba gratuita.","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-09-08 08:44:00","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-27 17:18:21","updated":"2026-09-08 08:44:00","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/es\/\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAutenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.protectimus.com\/es\/"},{"label":"Autenticaci\u00f3n RADIUS con MFA: proteja cada punto de acceso a la red","link":"https:\/\/www.protectimus.com\/es\/radius-authentication\/"}],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18589","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/comments?post=18589"}],"version-history":[{"count":1,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18589\/revisions"}],"predecessor-version":[{"id":18590,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18589\/revisions\/18590"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/media?parent=18589"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}