MFA for VPN: Add Two-Factor Authentication to Any VPN Gateway

VPN credentials have become the most reliable entry point for ransomware groups and state-sponsored attackers alike. A password on a VPN gateway — without a second factor — is the functional equivalent of a front door with no deadbolt: technically locked, but not in any way that slows down a determined attacker with a credential list.

Protectimus adds MFA to any VPN gateway through a RADIUS proxy. Your existing gateway hardware stays exactly as it is. Your users authenticate to the same VPN client they’ve always used. The second factor appears as an additional step — a TOTP code from an authenticator app, a hardware token, or an SMS — before the session is established.

Quick Answer

Protectimus works as a RADIUS proxy between your VPN gateway and Active Directory or another identity source. When a user connects, the gateway forwards the RADIUS Access-Request to Protectimus, which validates the password against AD/LDAP and then issues a second-factor challenge. Only after both factors are verified does the gateway receive an Access-Accept and open the tunnel. No gateway replacement, no client-side agents, no changes to your network topology.

Key facts

MFA blocks over 99.2% of automated credential attacks

Microsoft

Microsoft’s Digital Defense Report 2025 found that enabling MFA eliminates more than 99.2% of automated account compromise attempts — the highest-impact single control against credential-based attacks. (Microsoft Digital Defense Report)

73% of network intrusions started through VPN compromise

IBM

Coalition’s 2025 Cyber Claims Report found that VPN compromise was the established entry vector in 73% of network intrusions — highlighting VPN credential compromise as one of the most common initial access methods observed in ransomware-related intrusions. (Coalition 2025 Cyber Claims Report)

Credential abuse in 22% of all breaches

Verizon

Verizon DBIR 2026 confirms that stolen credentials remain the #1 initial access vector, present in 22% of confirmed breaches — with VPN and remote access services consistently listed as primary targets.(Verizon 2026 Data Breach Investigations Report)

Key Takeaways

VPN MFA icon

Works with any RADIUS-compatible VPN

Cisco ASA, Fortinet FortiGate, Palo Alto GlobalProtect, SonicWall, Check Point, Juniper, OpenVPN, MikroTik, and 15+ others.

RADIUS MFA icon

No gateway replacement

Protectimus inserts as a RADIUS proxy; existing VPN infrastructure remains in place, with only RADIUS authentication configured.

Versatile Tokens icon

TOTP app, SMS, email OTP, chatbot OTP, hardware tokens

Multiple second-factor methods to fit different user populations and security policies.

On-premise MFA platform icon

On-premises or cloud

Deploy Protectimus inside your network perimeter or use the cloud service; the On-Premise MFA Platform supports Active Directory and LDAP synchronization, while both deployment options support the same MFA methods and RADIUS integration.

On-Premise MFA Platform – Security feature: A Cluster-Based, Fault-Tolerant System

One server secures all VPNs

A single Protectimus RADIUS proxy can serve multiple VPN gateways simultaneously.

Customer Stories section icon – real-life client experiences

Deploy in one day

Standard single-gateway deployments complete in under 8 hours from installation to live enforcement.

Why VPN Access Is the #1 Target in 2026

The pattern is consistent across every major threat intelligence report published in the last two years: attackers go for VPN first, because VPN is the front door to everything else.

A successful VPN authentication puts an attacker inside the network with the same access as a legitimate remote employee. From that position they can reach file shares, internal applications, domain controllers, and every other resource that isn’t additionally segmented. The cost of a VPN credential — measured in what it unlocks — is enormous relative to the effort required to obtain one.

Credential stuffing is the primary technique. Billions of username/password pairs from historical breaches circulate freely on criminal forums. Automated tools cycle through these lists against VPN endpoints continuously. Even a 0.1% success rate against a large credential list produces hundreds of working sessions.

The threat actor landscape targeting VPN credentials is no longer just opportunistic criminals. Rapid7 and Cisco PSIRT documented that ransomware groups Akira and LockBit ran sustained brute-force campaigns specifically targeting Cisco ASA VPN endpoints in 2025. GreyNoise observed over 25,000 unique IP addresses scanning Cisco ASA login portals in a single campaign spike in August 2025. CISA has issued emergency directives for critical vulnerabilities in Fortinet, Ivanti, and Cisco VPN products in the last 18 months — in each case, attackers targeted the VPN authentication layer through credential attacks, authentication bypasses, or vulnerabilities affecting the VPN gateway itself.

Software vulnerabilities get patched. Credential-based attacks don’t require an unpatched appliance — they just require that the target accepts passwords without a second factor.

How Protectimus Adds MFA to VPN Authentication

The architecture is a RADIUS proxy insertion. Protectimus sits between your VPN gateway and your existing directory (Active Directory or LDAP), receiving authentication requests and enforcing a second factor before returning an Access-Accept.

 

Authentication flow

User
VPN Client
Enters username and password
 
VPN Gateway
Cisco AnyConnect / FortiGate / GlobalProtect / etc.
RADIUS Access-Request
 
Protectimus RADIUS Server
Validates password via AD / LDAP

Returns Access-Challenge (OTP Prompt)
OTP prompt is displayed
 
User
Enters a one-time password
RADIUS Access-Request (OTP)
 
Protectimus RADIUS Server
Validates OTP

Returns Access-Accept
 
VPN Gateway
Secure VPN session established

 

Access-Challenge vs Inline Mode

Most modern VPN clients — Cisco AnyConnect, Fortinet SSL VPN client, Palo Alto GlobalProtect — support RADIUS Access-Challenge natively. After entering their password, the user sees a secondary OTP prompt within the VPN client interface. This is the cleanest user experience and requires no changes to the client configuration.

For legacy VPN clients or gateway firmware versions that don’t correctly handle Access-Challenge, Protectimus provides Inline Mode. The user enters their password and OTP in a single authentication field, separated by a configurable delimiter (for example: MyPassword,123456). Protectimus parses the combined input, validates each component separately, and returns the appropriate response. Inline Mode works with virtually any RFC 2865-compliant RADIUS client.

One operational note: the default RADIUS timeout on many VPN gateways is 5 seconds — designed for instant password validation, not for a user retrieving a TOTP code. Increase this to at least 30 seconds on the gateway side before going live. One of the most common causes of failed test deployments is leaving the default RADIUS timeout unchanged.

Supported VPN & Remote Access Platforms

Protectimus has documented and tested integrations with the following VPN gateways, remote access platforms, and RADIUS-enabled solutions. Any RFC 2865-compliant RADIUS client can also be integrated, even if not listed below.

 

Vendor

Platform / Product

Integration Guide

Array Networks

AG SSL VPN

Setup Instructions

Aruba

ClearPass

Configuration Guide

Barracuda

SSL VPN

Setup Guide

Check Point

Mobile Access

Integration Steps

Cisco

AnyConnect (ASA, Firepower FTD)

Configuration Guide

Cisco

Meraki Client VPN

Setup Instructions

Cisco

Switches (RADIUS Authentication)

Setup Guide

Citrix

ADC / Gateway

Integration Guide

F5

BIG-IP APM

Configuration Steps

Forcepoint

VPN

Setup Guide

Fortinet

FortiGate VPN

Configuration Guide

Ivanti

Connect Secure (formerly Pulse Connect Secure)

Setup Instructions

Juniper

VPN

Integration Steps

MikroTik

RouterOS VPN

Configuration Guide

Microsoft

Windows Server VPN (RRAS)

Guide Link

NComputing

vSpace

Configuration Steps

NetApp

VDS

Integration Guide

Nerdio

Nerdio

Guide Link

OpenVPN

OpenVPN

Setup Guide Link

Netgate

pfSense (OpenVPN)

Setup Instructions

Palo Alto Networks

GlobalProtect

Integration Steps

Parallels

RAS

Guide Link

SonicWall

VPN

Setup Guide

VMware

Horizon View

Configuration Guide

WatchGuard

Mobile VPN

Setup Instructions

 

For a complete overview of Protectimus RADIUS authentication with MFA for VPN, VDI, Wi-Fi, and other RADIUS-enabled services, see the dedicated RADIUS page. For the Protectimus RADIUS component product page with installation details and system requirements, see the RADIUS component page.

Supported Authentication Methods

Method

How it delivers the OTP

Best for

Works without internet on user device

TOTP via Protectimus SMART app

Authenticator app that generates 30-second codes

Most enterprise users with smartphones

Yes

Hardware TOTP tokens

Physical device generates codes

Air-gapped environments, users without smartphones, high-security roles

Yes

SMS OTP

6-digit code via SMS

Users without smartphones or reliable Internet access

No (requires mobile signal)

Email OTP

6-digit code via email

Organizations that prefer email-based OTP delivery

No

Chatbot OTP

OTP via Telegram or Viber bot

Organizations looking for a convenient, low-cost alternative to SMS OTP

No

 

VPN-specific consideration: methods that require an active internet connection on the user’s device (SMS, email, chatbot) work for most VPN users since they typically have connectivity before connecting. TOTP via authenticator app and hardware tokens work even when the user’s device has no network connection — the code is generated locally and doesn’t require any external service.

For users who need physical hardware TOTP tokens — whether due to device restrictions, compliance requirements, or personal preference — Protectimus supports Slim NFC, TWO, FLEX, and SHARK models, as well as any OATH TOTP/HOTP/OCRA-compatible third-party token.

Deployment Options

Cloud RADIUS MFA service

Protectimus Cloud MFA Service works together with the Protectimus RADIUS Server. Your VPN gateway authenticates users against the Protectimus RADIUS Server, which securely communicates with the Protectimus Cloud MFA Service to validate the second factor. This deployment eliminates the need to host your own MFA platform while keeping deployment simple and lightweight.

On-premises RADIUS MFA server

The Protectimus RADIUS Server installs on a Windows or Linux server inside your network. All RADIUS traffic stays on-premises. When used with the Protectimus On-Premise MFA Platform, you can also synchronize users from Active Directory or LDAP for centralized identity management. Suitable for organizations with data residency requirements, air-gapped networks, or security policies that prohibit cloud authentication services. See the  on-premises MFA platform page for deployment specs.

High availability

In on-premises deployments, the Protectimus Platform can be deployed as a multi-node cluster. Since the Protectimus RADIUS Server is installed on each platform node, RADIUS authentication benefits from the same high-availability architecture. When using the Protectimus Cloud MFA Service, high availability can be achieved by deploying redundant Protectimus RADIUS Server instances.

Step-by-Step: How to Add MFA to Your VPN in 5 Steps

Step 1 — Deploy Protectimus. Choose the Protectimus Cloud MFA Service or the Protectimus On-Premise MFA Platform. If you choose the Cloud MFA Service, create an account at service.protectimus.com, then install and configure the Protectimus RADIUS Server on a Windows or Linux server inside your network. If you choose the On-Premise Platform, install both the platform and the Protectimus RADIUS Server.

Step 2 — Configure the RADIUS client on your gateway. Add Protectimus as a RADIUS server in your gateway’s AAA configuration. Set the server IP, shared secret, and authentication port (UDP 1812). Set the RADIUS timeout to at least 30 seconds.

Step 3 — Point the gateway to Protectimus. Update the authentication server reference in your VPN tunnel group or connection profile to use the Protectimus RADIUS Server. Configure the appropriate authentication provider (LDAP, Active Directory, RADIUS Proxy, or another supported option) in the Protectimus RADIUS Server.

Step 4 — Configure users. If you are using the Protectimus On-Premise Platform, configure Active Directory or LDAP synchronization and import users from the required organizational units or security groups. If you are using the Protectimus Cloud MFA Service, add users manually.

Step 5 — Enroll users and test. Send self-enrollment links to a pilot group. Users scan a QR code to register their authenticator app or authenticate using an assigned hardware token. Test the full flow: connect via VPN, enter credentials, verify the OTP prompt appears, confirm the session opens with a valid code. Then extend to the full user population.

For vendor-specific screenshots and CLI commands, use the integration guide links in the vendor table above.

Compliance

PCI DSS v4.0 (Requirements 8.4.2 and 8.4.3): Requirement 8.4.3 mandates MFA for all remote access to the cardholder data environment from outside the organization’s network — VPN access is the primary scenario in scope. Requirement 8.4.2 extends this to all CDE access regardless of connection method.

NIST SP 800-63B (AAL2): Authenticator Assurance Level 2 requires two distinct authentication factors for access to sensitive systems. TOTP via authenticator app or hardware token satisfies AAL2 directly.

HIPAA (45 CFR § 164.312): Technical Safeguards require access controls for systems containing electronic protected health information. MFA for VPN access helps organizations meet the access control requirements of this safeguard.

NIS2 Directive (Article 21): Essential and important entities must implement multi-factor or continuous authentication for access to network and information systems. VPN MFA covers the remote access scenarios explicitly called out in ENISA implementation guidance.

ISO/IEC 27001:2022 (Annex A 8.5): Secure authentication controls explicitly recommended for remote access and privileged account scenarios.

Protectimus vs Other VPN MFA Solutions

Factor

Protectimus

Duo Security

Azure MFA / NPS Extension

RSA SecurID

Deployment model

Cloud or on-premises

Cloud (proxy on-prem)

Cloud (Entra ID required)

Cloud or on-premises

RADIUS support

Native proxy

Via Duo Authentication Proxy

Via NPS Extension

Native

Agent required on gateway

No

No

No (NPS Extension on NPS server)

No

Hardware token support

Full OATH TOTP/HOTP

Limited

Limited (P1/P2 license required)

RSA tokens only

Air-gapped environments

Yes (on-prem)

No

No

Yes (on-prem)

Direct on-prem AD (no Entra)

Yes

Via proxy/agent

Requires Entra ID Connect

Yes

Pricing model

Per-user subscription

Per-user subscription

Included in Entra ID P1/P2

Per-user license

Vendor lock-in

Independent

Cisco/Duo ecosystem

Microsoft ecosystem

RSA ecosystem

 

The comparison is factual. Duo works well for organizations already standardized on the Cisco/Duo stack. Azure MFA NPS Extension is the lowest-friction choice for organizations with Entra ID P1/P2 licenses already in place. RSA SecurID suits environments with existing RSA infrastructure. Protectimus is the strongest choice when on-premises deployment, full hardware token support, or independence from a specific vendor ecosystem is required.

Learn more about protecting Active Directory with MFA on our MFA for Active Directory page.

FAQ

Yes. Protectimus operates as a RADIUS proxy — your gateway keeps its existing configuration and continues talking RADIUS exactly as before, just to a different server IP. No firmware updates, no hardware changes, no downtime during the cutover.

Use Inline Mode. The user enters their password and OTP in a single field with a configured separator (for example, a comma or a specific character). Protectimus parses the combined input and validates each part separately. This works with any RADIUS client, including legacy configurations that predate challenge/response support.

Yes. Register each gateway as a separate RADIUS client in Protectimus with its own shared secret. All gateways point to the same Protectimus RADIUS endpoint. User enrollments are shared — a user’s registered token works across all gateways from a single enrollment.

Yes. Deploy redundant Protectimus RADIUS Servers and configure your VPN gateway to fail over automatically if the primary server becomes unavailable. When using the Protectimus On-Premise MFA Platform, the platform can also be deployed as a high-availability cluster.

Yes. Protectimus offers an On-Premise MFA Platform that is deployed entirely within your own infrastructure. It can be installed on a single server or as a high-availability cluster, with all authentication processing remaining inside your network. See the  on-premises MFA platform page for system requirements and deployment options.

Any OATH TOTP, OCRA or HOTP-compatible hardware token. Protectimus offers four  TOTP tokens models — Slim NFC (card format, programmable), TWO (classic key fob, SHA-1), FLEX (key fob, programmable), SHARK (classic key fob, SHA-256) — as well as compatibility with third-party OATH tokens from other manufacturers. See  hardware TOTP tokens for the full list.

A single-gateway deployment — one AD directory, one VPN gateway, standard TOTP method — typically completes in under 8 hours from start to live enforcement, including user pilot testing. Multi-gateway and multi-domain environments take longer depending on the number of integrations; the RADIUS configuration itself is the same for each gateway.

Start Securing Your VPN Today

Every day a VPN endpoint accepts passwords without a second factor, it’s a target. Protectimus adds MFA to your VPN in one day without replacing your gateway or disrupting your users.

Free for up to 10 users, with a $25 testing credit — no credit card required.

Send Us A Message icon

Отправьте нам сообщение

    Этот сайт зарегистрирован на wpml.org как сайт разработки. Переключитесь на рабочий сайт по ключу remove this banner.