MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway
VPN credentials have become the most reliable entry point for ransomware groups and state-sponsored attackers alike. A password on a VPN gateway — without a second factor — is the functional equivalent of a front door with no deadbolt: technically locked, but not in any way that slows down a determined attacker with a credential list.
Protectimus adds MFA to any VPN gateway through a RADIUS proxy. Your existing gateway hardware stays exactly as it is. Your users authenticate to the same VPN client they’ve always used. The second factor appears as an additional step — a TOTP code from an authenticator app, a hardware token, or an SMS — before the session is established.
Table of Contents
Quick Answer
Protectimus works as a RADIUS proxy between your VPN gateway and Active Directory or another identity source. When a user connects, the gateway forwards the RADIUS Access-Request to Protectimus, which validates the password against AD/LDAP and then issues a second-factor challenge. Only after both factors are verified does the gateway receive an Access-Accept and open the tunnel. No gateway replacement, no client-side agents, no changes to your network topology.
Key facts
MFA blocks over 99.2% of automated credential attacks
Microsoft’s Digital Defense Report 2025 found that enabling MFA eliminates more than 99.2% of automated account compromise attempts — the highest-impact single control against credential-based attacks. (Microsoft Digital Defense Report)
73% of network intrusions started through VPN compromise
Coalition’s 2025 Cyber Claims Report found that VPN compromise was the established entry vector in 73% of network intrusions — highlighting VPN credential compromise as one of the most common initial access methods observed in ransomware-related intrusions. (Coalition 2025 Cyber Claims Report)
Credential abuse in 22% of all breaches
Verizon DBIR 2026 confirms that stolen credentials remain the #1 initial access vector, present in 22% of confirmed breaches — with VPN and remote access services consistently listed as primary targets.(Verizon 2026 Data Breach Investigations Report)
Key Takeaways
Works with any RADIUS-compatible VPN
Cisco ASA, Fortinet FortiGate, Palo Alto GlobalProtect, SonicWall, Check Point, Juniper, OpenVPN, MikroTik, and 15+ others.
No gateway replacement
Protectimus inserts as a RADIUS proxy; existing VPN infrastructure remains in place, with only RADIUS authentication configured.
TOTP app, SMS, email OTP, chatbot OTP, hardware tokens
Multiple second-factor methods to fit different user populations and security policies.
On-premises or cloud
Deploy Protectimus inside your network perimeter or use the cloud service; the On-Premise MFA Platform supports Active Directory and LDAP synchronization, while both deployment options support the same MFA methods and RADIUS integration.
One server secures all VPNs
A single Protectimus RADIUS proxy can serve multiple VPN gateways simultaneously.
Deploy in one day
Standard single-gateway deployments complete in under 8 hours from installation to live enforcement.
Why VPN Access Is the #1 Target in 2026
The pattern is consistent across every major threat intelligence report published in the last two years: attackers go for VPN first, because VPN is the front door to everything else.
A successful VPN authentication puts an attacker inside the network with the same access as a legitimate remote employee. From that position they can reach file shares, internal applications, domain controllers, and every other resource that isn’t additionally segmented. The cost of a VPN credential — measured in what it unlocks — is enormous relative to the effort required to obtain one.
Credential stuffing is the primary technique. Billions of username/password pairs from historical breaches circulate freely on criminal forums. Automated tools cycle through these lists against VPN endpoints continuously. Even a 0.1% success rate against a large credential list produces hundreds of working sessions.
The threat actor landscape targeting VPN credentials is no longer just opportunistic criminals. Rapid7 and Cisco PSIRT documented that ransomware groups Akira and LockBit ran sustained brute-force campaigns specifically targeting Cisco ASA VPN endpoints in 2025. GreyNoise observed over 25,000 unique IP addresses scanning Cisco ASA login portals in a single campaign spike in August 2025. CISA has issued emergency directives for critical vulnerabilities in Fortinet, Ivanti, and Cisco VPN products in the last 18 months — in each case, attackers targeted the VPN authentication layer through credential attacks, authentication bypasses, or vulnerabilities affecting the VPN gateway itself.
Software vulnerabilities get patched. Credential-based attacks don’t require an unpatched appliance — they just require that the target accepts passwords without a second factor.
How Protectimus Adds MFA to VPN Authentication
The architecture is a RADIUS proxy insertion. Protectimus sits between your VPN gateway and your existing directory (Active Directory or LDAP), receiving authentication requests and enforcing a second factor before returning an Access-Accept.
Authentication flow
VPN Client
Cisco AnyConnect / FortiGate / GlobalProtect / etc.
Validates password via AD / LDAP
Returns Access-Challenge (OTP Prompt)
Enters a one-time password
Validates OTP
Returns Access-Accept
Secure VPN session established
Access-Challenge vs Inline Mode
Most modern VPN clients — Cisco AnyConnect, Fortinet SSL VPN client, Palo Alto GlobalProtect — support RADIUS Access-Challenge natively. After entering their password, the user sees a secondary OTP prompt within the VPN client interface. This is the cleanest user experience and requires no changes to the client configuration.
For legacy VPN clients or gateway firmware versions that don’t correctly handle Access-Challenge, Protectimus provides Inline Mode. The user enters their password and OTP in a single authentication field, separated by a configurable delimiter (for example: MyPassword,123456). Protectimus parses the combined input, validates each component separately, and returns the appropriate response. Inline Mode works with virtually any RFC 2865-compliant RADIUS client.
One operational note: the default RADIUS timeout on many VPN gateways is 5 seconds — designed for instant password validation, not for a user retrieving a TOTP code. Increase this to at least 30 seconds on the gateway side before going live. One of the most common causes of failed test deployments is leaving the default RADIUS timeout unchanged.
Supported VPN & Remote Access Platforms
Protectimus has documented and tested integrations with the following VPN gateways, remote access platforms, and RADIUS-enabled solutions. Any RFC 2865-compliant RADIUS client can also be integrated, even if not listed below.
Vendor | Platform / Product | Integration Guide |
Array Networks | AG SSL VPN | |
| Aruba | ClearPass | |
Barracuda | SSL VPN | Setup Guide |
Check Point | Mobile Access | |
Cisco | AnyConnect (ASA, Firepower FTD) | |
Cisco | Meraki Client VPN | |
Cisco | Switches (RADIUS Authentication) | |
Citrix | ADC / Gateway | |
F5 | BIG-IP APM | |
Forcepoint | VPN | |
Fortinet | FortiGate VPN | |
Ivanti | Connect Secure (formerly Pulse Connect Secure) | |
Juniper | VPN | |
MikroTik | RouterOS VPN | |
Microsoft | Windows Server VPN (RRAS) | |
NComputing | vSpace | |
NetApp | VDS | |
Nerdio | Nerdio | |
OpenVPN | OpenVPN | |
Netgate | pfSense (OpenVPN) | |
Palo Alto Networks | GlobalProtect | |
Parallels | RAS | |
SonicWall | VPN | |
VMware | Horizon View | |
WatchGuard | Mobile VPN | Setup Instructions |
For a complete overview of Protectimus RADIUS authentication with MFA for VPN, VDI, Wi-Fi, and other RADIUS-enabled services, see the dedicated RADIUS page. For the Protectimus RADIUS component product page with installation details and system requirements, see the RADIUS component page.
Supported Authentication Methods
Method | How it delivers the OTP | Best for | Works without internet on user device |
|---|---|---|---|
Authenticator app that generates 30-second codes | Most enterprise users with smartphones | Yes | |
Physical device generates codes | Air-gapped environments, users without smartphones, high-security roles | Yes | |
6-digit code via SMS | Users without smartphones or reliable Internet access | No (requires mobile signal) | |
6-digit code via email | Organizations that prefer email-based OTP delivery | No | |
OTP via Telegram or Viber bot | Organizations looking for a convenient, low-cost alternative to SMS OTP | No |
VPN-specific consideration: methods that require an active internet connection on the user’s device (SMS, email, chatbot) work for most VPN users since they typically have connectivity before connecting. TOTP via authenticator app and hardware tokens work even when the user’s device has no network connection — the code is generated locally and doesn’t require any external service.
For users who need physical hardware TOTP tokens — whether due to device restrictions, compliance requirements, or personal preference — Protectimus supports Slim NFC, TWO, FLEX, and SHARK models, as well as any OATH TOTP/HOTP/OCRA-compatible third-party token.
Deployment Options
Cloud RADIUS MFA service
Protectimus Cloud MFA Service works together with the Protectimus RADIUS Server. Your VPN gateway authenticates users against the Protectimus RADIUS Server, which securely communicates with the Protectimus Cloud MFA Service to validate the second factor. This deployment eliminates the need to host your own MFA platform while keeping deployment simple and lightweight.
On-premises RADIUS MFA server
The Protectimus RADIUS Server installs on a Windows or Linux server inside your network. All RADIUS traffic stays on-premises. When used with the Protectimus On-Premise MFA Platform, you can also synchronize users from Active Directory or LDAP for centralized identity management. Suitable for organizations with data residency requirements, air-gapped networks, or security policies that prohibit cloud authentication services. See the on-premises MFA platform page for deployment specs.
High availability
In on-premises deployments, the Protectimus Platform can be deployed as a multi-node cluster. Since the Protectimus RADIUS Server is installed on each platform node, RADIUS authentication benefits from the same high-availability architecture. When using the Protectimus Cloud MFA Service, high availability can be achieved by deploying redundant Protectimus RADIUS Server instances.
Step-by-Step: How to Add MFA to Your VPN in 5 Steps
Step 1 — Deploy Protectimus. Choose the Protectimus Cloud MFA Service or the Protectimus On-Premise MFA Platform. If you choose the Cloud MFA Service, create an account at service.protectimus.com, then install and configure the Protectimus RADIUS Server on a Windows or Linux server inside your network. If you choose the On-Premise Platform, install both the platform and the Protectimus RADIUS Server.
Step 2 — Configure the RADIUS client on your gateway. Add Protectimus as a RADIUS server in your gateway’s AAA configuration. Set the server IP, shared secret, and authentication port (UDP 1812). Set the RADIUS timeout to at least 30 seconds.
Step 3 — Point the gateway to Protectimus. Update the authentication server reference in your VPN tunnel group or connection profile to use the Protectimus RADIUS Server. Configure the appropriate authentication provider (LDAP, Active Directory, RADIUS Proxy, or another supported option) in the Protectimus RADIUS Server.
Step 4 — Configure users. If you are using the Protectimus On-Premise Platform, configure Active Directory or LDAP synchronization and import users from the required organizational units or security groups. If you are using the Protectimus Cloud MFA Service, add users manually.
Step 5 — Enroll users and test. Send self-enrollment links to a pilot group. Users scan a QR code to register their authenticator app or authenticate using an assigned hardware token. Test the full flow: connect via VPN, enter credentials, verify the OTP prompt appears, confirm the session opens with a valid code. Then extend to the full user population.
For vendor-specific screenshots and CLI commands, use the integration guide links in the vendor table above.
Compliance
PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3): Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment from outside the organization’s network — VPN access is the primary scenario in scope. Requirement 8.4.2 extends this to all CDE access regardless of connection method.
NIST SP 800-63B (AAL2): Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 directly.
HIPAA (45 CFR § 164.312): Technical Safeguards require access controls for systems containing electronic protected health information. MFA for VPN access helps organizations meet the access control requirements of this safeguard.
NIS2 Directive (Article 21): Essential and important entities must implement multi-factor or continuous authentication for access to network and information systems. VPN MFA covers the remote access scenarios explicitly called out in ENISA implementation guidance.
ISO/IEC 27001:2022 (Annex A 8.5): Secure authentication controls explicitly recommended for remote access and privileged account scenarios.
Protectimus vs Other VPN MFA Solutions
Factor | Protectimus | Duo Security | Azure MFA / NPS Extension | RSA SecurID |
|---|---|---|---|---|
Deployment model | Cloud or on-premises | Cloud (proxy on-prem) | Cloud (Entra ID required) | Cloud or on-premises |
RADIUS support | Native proxy | Via Duo Authentication Proxy | Via NPS Extension | Native |
Agent required on gateway | No | No | No (NPS Extension on NPS server) | No |
Hardware token support | Full OATH TOTP/HOTP | Limited | Limited (P1/P2 license required) | RSA tokens only |
Air-gapped environments | Yes (on-prem) | No | No | Yes (on-prem) |
Direct on-prem AD (no Entra) | Yes | Via proxy/agent | Requires Entra ID Connect | Yes |
Pricing model | Per-user subscription | Per-user subscription | Included in Entra ID P1/P2 | Per-user license |
Vendor lock-in | Independent | Cisco/Duo ecosystem | Microsoft ecosystem | RSA ecosystem |
The comparison is factual. Duo works well for organizations already standardized on the Cisco/Duo stack. Azure MFA NPS Extension is the lowest-friction choice for organizations with Entra ID P1/P2 licenses already in place. RSA SecurID suits environments with existing RSA infrastructure. Protectimus is the strongest choice when on-premises deployment, full hardware token support, or independence from a specific vendor ecosystem is required.
Learn more about protecting Active Directory with MFA on our MFA for Active Directory page.
FAQ
Does it work without replacing my VPN gateway?
Yes. Protectimus operates as a RADIUS proxy — your gateway keeps its existing configuration and continues talking RADIUS exactly as before, just to a different server IP. No firmware updates, no hardware changes, no downtime during the cutover.
What if my VPN client has no separate OTP field?
Use Inline Mode. The user enters their password and OTP in a single field with a configured separator (for example, a comma or a specific character). Protectimus parses the combined input and validates each part separately. This works with any RADIUS client, including legacy configurations that predate challenge/response support.
Can I secure multiple VPN gateways with one Protectimus server?
Yes. Register each gateway as a separate RADIUS client in Protectimus with its own shared secret. All gateways point to the same Protectimus RADIUS endpoint. User enrollments are shared — a user’s registered token works across all gateways from a single enrollment.
Does it support high availability?
Yes. Deploy redundant Protectimus RADIUS Servers and configure your VPN gateway to fail over automatically if the primary server becomes unavailable. When using the Protectimus On-Premise MFA Platform, the platform can also be deployed as a high-availability cluster.
Is there an on-premises option?
Yes. Protectimus offers an On-Premise MFA Platform that is deployed entirely within your own infrastructure. It can be installed on a single server or as a high-availability cluster, with all authentication processing remaining inside your network. See the on-premises MFA platform page for system requirements and deployment options.
Which hardware tokens work with VPN MFA?
Any OATH TOTP, OCRA or HOTP-compatible hardware token. Protectimus offers four TOTP tokens models — Slim NFC (card format, programmable), TWO (classic key fob, SHA-1), FLEX (key fob, programmable), SHARK (classic key fob, SHA-256) — as well as compatibility with third-party OATH tokens from other manufacturers. See hardware TOTP tokens for the full list.
How long does VPN MFA deployment take?
A single-gateway deployment — one AD directory, one VPN gateway, standard TOTP method — typically completes in under 8 hours from start to live enforcement, including user pilot testing. Multi-gateway and multi-domain environments take longer depending on the number of integrations; the RADIUS configuration itself is the same for each gateway.
Start Securing Your VPN Today
Every day a VPN endpoint accepts passwords without a second factor, it’s a target. Protectimus adds MFA to your VPN in one day without replacing your gateway or disrupting your users.
Free for up to 10 users, with a $25 testing credit — no credit card required.