ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)

ื”ืฆื•ืจืš ืœืกืคืง ื’ื™ืฉื” ืžืจื—ื•ืง ืœืกื‘ื™ื‘ื” ืืจื’ื•ื ื™ืช ืžืชืขื•ืจืจ ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื™ื•ืชืจ ื•ื™ื•ืชืจ, ืœื ืžืฉื ื” ืื ืืœื• ื”ืžืฉืชืžืฉื™ื ืฉืœืš ืื• ื”ืฉื•ืชืคื™ื ืฉื–ืงื•ืงื™ื ืœื’ื™ืฉื” ืœืฉืจืช ืžืกื•ื™ื ื‘ืืจื’ื•ืŸ ืฉืœืš.

ืœืžื˜ืจื•ืช ืืœื•, ืจื•ื‘ ื”ื—ื‘ืจื•ืช ืžืฉืชืžืฉื•ืช ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช VPN, ืืฉืจ ื”ื•ื›ื™ื—ื” ืืช ืขืฆืžื” ื›ื“ืจืš ืžื•ื’ื ืช ืžื”ื™ืžื ื” ืœืกืคืง ื’ื™ืฉื” ืœืžืฉืื‘ื™ื ื”ืžืงื•ืžื™ื™ื ืฉืœ ื”ืืจื’ื•ืŸ.

ื”ื—ื‘ืจื” ืฉืœื™ ืœื ื”ื™ื™ืชื” ื™ื•ืฆืืช ื“ื•ืคืŸ, ื•ืื ื—ื ื•, ื›ืžื• ืจื‘ื™ื ืื—ืจื™ื, ืžืฉืชืžืฉื™ื ื‘ื˜ื›ื ื•ืœื•ื’ื™ื” ื”ื–ื•. ื•ื›ืžื• ืจื‘ื™ื ืื—ืจื™ื, ืื ื• ืžืฉืชืžืฉื™ื ื‘-Cisco ASA 55xx ื›ืฉืขืจ ื’ื™ืฉื” ืžืจื—ื•ืง.

ื›ื›ืœ ืฉืžืกืคืจ ื”ืžืฉืชืžืฉื™ื ื”ืžืจื•ื—ืงื™ื ื’ื“ืœ, ื™ืฉ ืฆื•ืจืš ืœืคืฉื˜ ืืช ื”ืœื™ืš ื”ื ืคืงืช ื”ืื™ืฉื•ืจื™ื. ืืš ื™ื—ื“ ืขื ื–ืืช, ื™ืฉ ืœืขืฉื•ืช ื–ืืช ืžื‘ืœื™ ืœืคื’ื•ืข ื‘ื‘ื˜ื™ื—ื•ืช.

ืขื‘ื•ืจ ืขืฆืžื ื•, ืžืฆืื ื• ืคืชืจื•ืŸ ื‘ืฉื™ืžื•ืฉ ื‘ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ ืœื—ื™ื‘ื•ืจ ื‘ืืžืฆืขื•ืช Cisco SSL VPN, ื‘ืืžืฆืขื•ืช ืกื™ืกืžืื•ืช ื—ื“ ืคืขืžื™ื•ืช. ื•ื”ืคืจืกื•ื ื”ื–ื” ื™ืกืคืจ ืœื›ื ืื™ืš ืœืืจื’ืŸ ืคืชืจื•ืŸ ื›ื–ื” ื‘ืžื™ื ื™ืžื•ื ื–ืžืŸ ื•ืืคืก ืขืœื•ื™ื•ืช ืขื‘ื•ืจ ื”ืชื•ื›ื ื” ื”ื“ืจื•ืฉื” (ื‘ืชื ืื™ ืฉื›ื‘ืจ ื™ืฉ ืœื›ื Cisco ASA ื‘ืชืฉืชื™ืช ืฉืœื›ื).

ื”ืฉื•ืง ื’ื“ื•ืฉ ื‘ืคืชืจื•ื ื•ืช ืืจื’ื–ื™ื ืœื”ืคืงืช ืกื™ืกืžืื•ืช ื—ื“ ืคืขืžื™ื•ืช, ืชื•ืš ืฉื”ื•ื ืžืฆื™ืข ืืคืฉืจื•ื™ื•ืช ืจื‘ื•ืช ืœื”ืฉื’ืชืŸ, ื‘ื™ืŸ ืื ื–ื” ืฉืœื™ื—ืช ื”ืกื™ืกืžื” ื‘ืืžืฆืขื•ืช SMS ืื• ืฉื™ืžื•ืฉ ื‘ืืกื™ืžื•ื ื™ื, ื”ืŸ ื‘ื—ื•ืžืจื” ื•ื”ืŸ ื‘ืชื•ื›ื ื” (ืœืžืฉืœ, ื‘ื˜ืœืคื•ืŸ ื ื™ื™ื“). ืื‘ืœ ื”ืจืฆื•ืŸ ืœื—ืกื•ืš ื›ืกืฃ ื•ื”ืจืฆื•ืŸ ืœื—ืกื•ืš ื›ืกืฃ ืœืžืขืกื™ืง ืฉืœื™, ื‘ืžืฉื‘ืจ ื”ื ื•ื›ื—ื™, ืื™ืœืฆื• ืื•ืชื™ ืœืžืฆื•ื ื“ืจืš ื—ื™ื ืžื™ืช ืœื”ื˜ืžื™ืข ืฉื™ืจื•ืช ืœื”ืคืงืช ืกื™ืกืžืื•ืช ื—ื“ ืคืขืžื™ื•ืช. ืฉืืžื ื ื—ื™ื ืžื™, ืื‘ืœ ืœื ื ื—ื•ืช ื‘ื”ืจื‘ื” ืžืคืชืจื•ื ื•ืช ืžืกื—ืจื™ื™ื (ื›ืืŸ ื›ื“ืื™ ืœืขืฉื•ืช ื”ื–ืžื ื”, ืœืฆื™ื™ืŸ ืฉืœืžื•ืฆืจ ื”ื–ื” ื™ืฉ ื’ื ื’ืจืกื” ืžืกื—ืจื™ืช, ืื‘ืœ ื”ืกื›ืžื ื• ืฉื”ืขืœื•ื™ื•ืช ืฉืœื ื•, ื‘ื›ืกืฃ, ื™ื”ื™ื• ืืคืก).

ืื– ืื ื—ื ื• ืฆืจื™ื›ื™ื:

- ืชืžื•ื ืช ืœื™ื ื•ืงืก ืขื ืกื˜ ื›ืœื™ื ืžื•ื‘ื ื” - multiOTP, FreeRADIUS ื•-nginx, ืœื’ื™ืฉื” ืœืฉืจืช ื“ืจืš ื”ืื™ื ื˜ืจื ื˜ (http://download.multiotp.net/ - ื”ืฉืชืžืฉืชื™ ื‘ืชืžื•ื ื” ืžื•ื›ื ื” ืขื‘ื•ืจ VMware)
- ืฉืจืช Active Directory
โ€” Cisco ASA ืขืฆืžื” (ืžื˜ืขืžื™ ื ื•ื—ื•ืช, ืื ื™ ืžืฉืชืžืฉ ื‘-ASDM)
- ื›ืœ ืืกื™ืžื•ืŸ ืชื•ื›ื ื” ืฉืชื•ืžืš ื‘ืžื ื’ื ื•ืŸ TOTP (ืื ื™, ืœืžืฉืœ, ืžืฉืชืžืฉ ื‘-Google Authenticator, ืื‘ืœ ืื•ืชื• FreeOTP ื™ืขืฉื”)

ืื ื™ ืœื ืื›ื ืก ืœืคืจื˜ื™ื ืขืœ ืื™ืš ื”ืชืžื•ื ื” ืžืชืคืชื—ืช. ื›ืชื•ืฆืื” ืžื›ืš, ืชืงื‘ืœ Debian Linux ืขื multiOTP ื•-FreeRADIUS ืฉื›ื‘ืจ ืžื•ืชืงื ื™ื, ืžื•ื’ื“ืจื™ื ืœืขื‘ื•ื“ ื™ื—ื“ ื•ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ืœื ื™ื”ื•ืœ OTP.

ืฉืœื‘ 1. ืื ื• ืžืคืขื™ืœื™ื ืืช ื”ืžืขืจื›ืช ื•ืžื’ื“ื™ืจื™ื ืื•ืชื” ืขื‘ื•ืจ ื”ืจืฉืช ืฉืœืš
ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืžืขืจื›ืช ืžื’ื™ืขื” ืขื ืื™ืฉื•ืจื™ root root. ืื ื™ ื—ื•ืฉื‘ ืฉื›ื•ืœื ื ื™ื—ืฉื• ืฉื–ื” ื™ื”ื™ื” ืจืขื™ื•ืŸ ื˜ื•ื‘ ืœืฉื ื•ืช ืืช ืกื™ืกืžืช ืžืฉืชืžืฉ ื”ืฉื•ืจืฉ ืœืื—ืจ ื”ื›ื ื™ืกื” ื”ืจืืฉื•ื ื”. ืืชื” ื’ื ืฆืจื™ืš ืœืฉื ื•ืช ืืช ื”ื’ื“ืจื•ืช ื”ืจืฉืช (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื–ื” '192.168.1.44' ืขื ื”ืฉืขืจ '192.168.1.1'). ืœืื—ืจ ืžื›ืŸ ืชื•ื›ืœ ืœืืชื—ืœ ืืช ื”ืžืขืจื›ืช.

ื‘ื•ืื• ื ื™ืฆื•ืจ ืžืฉืชืžืฉ ื‘-Active Directory Otp, ืขื ืกื™ืกืžื” MySuperPassword.

ืฉืœื‘ 2. ื”ื’ื“ืจ ืืช ื”ื—ื™ื‘ื•ืจ ื•ื™ื™ื‘ื ืžืฉืชืžืฉื™ Active Directory
ืœืฉื ื›ืš, ืื ื• ื–ืงื•ืงื™ื ืœื’ื™ืฉื” ืœืงื•ื ืกื•ืœื”, ื•ื™ืฉื™ืจื•ืช ืœืงื•ื‘ืฅ multiotp.php, ื‘ืืžืฆืขื•ืชื• ื ื’ื“ื™ืจ ืืช ื”ื’ื“ืจื•ืช ื”ื—ื™ื‘ื•ืจ ืœ-Active Directory.

ืขื‘ื•ืจ ืœืกืคืจื™ื™ื” /usr/local/bin/multiotp/ ื•ื‘ืฆืข ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช ื‘ืชื•ืจืŸ:

./multiotp.php -config default-request-prefix-pin=0

ืงื•ื‘ืข ืื ื ื“ืจืฉืช ืกื™ื›ื” ื ื•ืกืคืช (ืงื‘ื•ืขื”) ื‘ืขืช ื”ื–ื ืช ืกื™ื›ื” ื—ื“ ืคืขืžื™ืช (0 ืื• 1)

./multiotp.php -config default-request-ldap-pwd=0

ืงื•ื‘ืข ืื ื ื“ืจืฉืช ืกื™ืกืžืช ื“ื•ืžื™ื™ืŸ ื‘ืขืช โ€‹โ€‹ื”ื–ื ืช ืกื™ื›ื” ื—ื“ ืคืขืžื™ืช (0 ืื• 1)

./multiotp.php -config ldap-server-type=1

ืกื•ื’ ืฉืจืช LDAP ืžืฆื•ื™ืŸ (0 = ืฉืจืช LDAP ืจื’ื™ืœ, ื‘ืžืงืจื” ืฉืœื ื• 1 = Active Directory)

./multiotp.php -config ldap-cn-identifier="sAMAccountName"

ืžืฆื™ื™ืŸ ืืช ื”ืคื•ืจืžื˜ ืฉื‘ื• ื™ื•ืฆื’ ืฉื ื”ืžืฉืชืžืฉ (ืขืจืš ื–ื” ื™ืฆื™ื’ ืจืง ืืช ื”ืฉื, ืœืœื ื”ื“ื•ืžื™ื™ืŸ)

./multiotp.php -config ldap-group-cn-identifier="sAMAccountName"

ืื•ืชื• ื“ื‘ืจ, ืจืง ืœืงื‘ื•ืฆื”

./multiotp.php -config ldap-group-attribute="memberOf"

ืžืฆื™ื™ืŸ ืฉื™ื˜ื” ืœืงื‘ื™ืขื” ืื ืžืฉืชืžืฉ ืฉื™ื™ืš ืœืงื‘ื•ืฆื”

./multiotp.php -config ldap-ssl=1

ื”ืื ืขืœื™ ืœื”ืฉืชืžืฉ ื‘ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ืœืฉืจืช LDAP (ื›ืžื•ื‘ืŸ, ื›ืŸ!)

./multiotp.php -config ldap-port=636

ื™ืฆื™ืื” ืœื—ื™ื‘ื•ืจ ืœืฉืจืช LDAP

./multiotp.php -config ldap-domain-controllers=adSRV.domain.local

ื›ืชื•ื‘ืช ืฉืจืช ื”-Active Directory ืฉืœืš

./multiotp.php -config ldap-base-dn="CN=Users,DC=domain,DC=local"

ืื ื• ืžืฆื™ื™ื ื™ื ื”ื™ื›ืŸ ืœื”ืชื—ื™ืœ ืœื—ืคืฉ ืžืฉืชืžืฉื™ื ื‘ื“ื•ืžื™ื™ืŸ

./multiotp.php -config ldap-bind-dn="[email protected]"

ืฆื™ื™ืŸ ืžืฉืชืžืฉ ืฉื™ืฉ ืœื• ื–ื›ื•ื™ื•ืช ื—ื™ืคื•ืฉ ื‘-Active Directory

./multiotp.php -config ldap-server-password="MySuperPassword"

ืฆื™ื™ืŸ ืืช ืกื™ืกืžืช ื”ืžืฉืชืžืฉ ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืœ-Active Directory

./multiotp.php -config ldap-network-timeout=10

ื”ื’ื“ืจืช ื–ืžืŸ ืงืฆื•ื‘ ืœื—ื™ื‘ื•ืจ ืœ-Active Directory

./multiotp.php -config ldap-time-limit=30

ืงื‘ืขื ื• ืžื’ื‘ืœืช ื–ืžืŸ ืœืคืขื•ืœืช ื™ื™ื‘ื•ื โ€‹โ€‹ื”ืžืฉืชืžืฉ

./multiotp.php -config ldap-activated=1

ื”ืคืขืœืช ืชืฆื•ืจืช ื”ื—ื™ื‘ื•ืจ ืฉืœ Active Directory

./multiotp.php -debug -display-log -ldap-users-sync

ืื ื• ืžื™ื™ื‘ืื™ื ืžืฉืชืžืฉื™ื ืž- Active Directory

ืฉืœื‘ 3. ืฆื•ืจ ืงื•ื“ QR ืขื‘ื•ืจ ื”ืืกื™ืžื•ืŸ
ื”ื›ืœ ื›ืืŸ ืคืฉื•ื˜ ื‘ื™ื•ืชืจ. ืคืชื—ื• ืืช ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ืฉืจืช ื”-OTP ื‘ื“ืคื“ืคืŸ, ื”ื™ื›ื ืกื• (ืืœ ืชืฉื›ื—ื• ืœืฉื ื•ืช ืืช ืกื™ืกืžืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืžื ื”ืœ!), ื•ืœื—ืฅ ืขืœ ื›ืคืชื•ืจ "ื”ื“ืคืก":

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
ื”ืชื•ืฆืื” ืฉืœ ืคืขื•ืœื” ื–ื• ืชื”ื™ื” ื“ืฃ ืฉื™ื›ื™ืœ ืฉื ื™ ืงื•ื“ื™ QR. ืื ื—ื ื• ืžืชืขืœืžื™ื ื‘ืื•ืžืฅ ืžื”ืจืืฉื•ืŸ ืฉื‘ื”ื (ืœืžืจื•ืช ื”ื›ืชื•ื‘ืช ื”ืื˜ืจืงื˜ื™ื‘ื™ืช Google Authenticator / Authenticator / 2 Steps Authenticator), ื•ืฉื•ื‘ ืื ื• ืกื•ืจืงื™ื ื‘ืื•ืžืฅ ืืช ื”ืงื•ื“ ื”ืฉื ื™ ืœืชื•ืš ืืกื™ืžื•ืŸ ืชื•ื›ื ื” ื‘ื˜ืœืคื•ืŸ:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
(ื›ืŸ, ื‘ื›ื•ื•ื ื” ืงืœืงืœืชื™ ืืช ืงื•ื“ ื”-QR ื›ื“ื™ ืฉื™ื”ื™ื” ื‘ืœืชื™ ืงืจื™ื).

ืœืื—ืจ ื”ืฉืœืžืช ืคืขื•ืœื•ืช ืืœื•, ืกื™ืกืžื” ื‘ืช ืฉืฉ ืกืคืจื•ืช ืชืชื—ื™ืœ ืœื”ื™ื•ื•ืฆืจ ื‘ืืคืœื™ืงืฆื™ื” ืฉืœืš ื›ืœ ืฉืœื•ืฉื™ื ืฉื ื™ื•ืช.

ื›ื“ื™ ืœื”ื™ื•ืช ื‘ื˜ื•ื—, ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื–ื” ื‘ืื•ืชื• ืžืžืฉืง:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
ืขืœ ื™ื“ื™ ื”ื–ื ืช ืฉื ื”ืžืฉืชืžืฉ ื•ื”ืกื™ืกืžื” ื”ื—ื“ ืคืขืžื™ืช ืžื”ืืคืœื™ืงืฆื™ื” ื‘ื˜ืœืคื•ืŸ. ื”ืื ืงื™ื‘ืœืช ืชืฉื•ื‘ื” ื—ื™ื•ื‘ื™ืช? ืื– ื‘ื•ืื• ื ืžืฉื™ืš ื”ืœืื”.

ืฉืœื‘ 4. ืชืฆื•ืจื” ื•ื‘ื“ื™ืงื” ื ื•ืกืคืช ืฉืœ ืคืขื•ืœืช FreeRADIUS
ื›ืคื™ ืฉืฆื™ื™ื ืชื™ ืœืขื™ืœ, multiOTP ื›ื‘ืจ ืžื•ื’ื“ืจ ืœืขื‘ื•ื“ ืขื FreeRADIUS, ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื”ืจื™ืฅ ื‘ื“ื™ืงื•ืช ื•ืœื”ื•ืกื™ืฃ ืžื™ื“ืข ืขืœ ืฉืขืจ ื”-VPN ืฉืœื ื• ืœืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืฉืœ FreeRADIUS.

ืื ื—ื ื• ื—ื•ื–ืจื™ื ืœืงื•ื ืกื•ืœืช ื”ืฉืจืช, ืœืกืคืจื™ื™ื” /usr/local/bin/multiotp/, ืœื”ื™ื›ื ืก:

./multiotp.php -config debug=1
./multiotp.php -config display-log=1

ื›ื•ืœืœ ืจื™ืฉื•ื ืžืคื•ืจื˜ ื™ื•ืชืจ.

ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ืฉืœ ืœืงื•ื—ื•ืช FreeRADIUS (/etc/freeeradius/clinets.conf) ื”ืขืจื” ืืช ื›ืœ ื”ืฉื•ืจื•ืช ื”ืงืฉื•ืจื•ืช localhost ื•ื”ื•ืกืฃ ืฉื ื™ ืขืจื›ื™ื:

client localhost {
        ipaddr = 127.0.0.1
        secret          = testing321
        require_message_authenticator = no
}

- ืœืžื‘ื—ืŸ

client 192.168.1.254/32 {
        shortname =     CiscoASA
        secret =        ConnectToRADIUSSecret
}

- ืขื‘ื•ืจ ืฉืขืจ ื”-VPN ืฉืœื ื•.

ื”ืคืขืœ ืžื—ื“ืฉ ืืช FreeRADIUS ื•ื ืกื” ืœื”ื™ื›ื ืก:

radtest username 100110 localhost 1812 testing321

ืื™ืคื” ืฉื ืžืฉืชืžืฉ = ืฉื ืžืฉืชืžืฉ, 100110 = ืกื™ืกืžื” ืฉื ื™ืชื ื” ืœื ื• ืขืœ ื™ื“ื™ ื”ืืคืœื™ืงืฆื™ื” ื‘ื˜ืœืคื•ืŸ, localhost = ื›ืชื•ื‘ืช ืฉืจืช RADIUS, 1812 - ื™ืฆื™ืืช ืฉืจืช RADIUS, testing321 - ืกื™ืกืžืช ืœืงื•ื— ืฉืจืช RADIUS (ืฉืฆื™ื™ื ื• ื‘ืชืฆื•ืจื”).

ื”ืชื•ืฆืื” ืฉืœ ืคืงื•ื“ื” ื–ื• ืชื•ืฆื ื‘ืขืจืš ื›ืš:

Sending Access-Request of id 44 to 127.0.0.1 port 1812
        User-Name = "username"
        User-Password = "100110"
        NAS-IP-Address = 127.0.1.1
        NAS-Port = 1812
        Message-Authenticator = 0x00000000000000000000000000000000
rad_recv: Access-Accept packet from host 127.0.0.1 port 1812, id=44, length=20

ื›ืขืช ืขืœื™ื ื• ืœื•ื•ื“ื ืฉื”ืžืฉืชืžืฉ ืžืื•ืžืช ื‘ื”ืฆืœื—ื”. ืœืฉื ื›ืš, ื ืกืชื›ืœ ืขืœ ื”ื™ื•ืžืŸ ืฉืœ multiotp ืขืฆืžื•:

tail /var/log/multiotp/multiotp.log

ื•ืื ื”ืขืจืš ื”ืื—ืจื•ืŸ ื™ืฉ:

2016-09-01 08:58:17     notice  username  User    OK: User username successfully logged in from 127.0.0.1
2016-09-01 08:58:17     debug           Debug   Debug: 0 OK: Token accepted from 127.0.0.1

ื•ืื– ื”ื›ืœ ื”ืœืš ื›ืฉื•ืจื” ื•ื ื•ื›ืœ ืœื”ืฉืœื™ื

ืฉืœื‘ 5: ื”ื’ื“ืจ ืืช Cisco ASA
ื‘ื•ืื• ื ืกื›ื™ื ืฉื›ื‘ืจ ื™ืฉ ืœื ื• ืงื‘ื•ืฆื” ืžื•ื’ื“ืจืช ื•ืžื“ื™ื ื™ื•ืช ืœื’ื™ืฉื” ื“ืจืš SLL VPN, ื”ืžื•ื’ื“ืจื™ื ื‘ืฉื™ืœื•ื‘ ืขื Active Directory, ื•ืขืœื™ื ื• ืœื”ื•ืกื™ืฃ ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ ืขื‘ื•ืจ ืคืจื•ืคื™ืœ ื–ื”.

1. ื”ื•ืกืฃ ืงื‘ื•ืฆืช ืฉืจืช AAA ื—ื“ืฉื”:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
2. ื”ื•ืกืฃ ืืช ืฉืจืช ื”-multiOTP ืฉืœื ื• ืœืงื‘ื•ืฆื”:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
3. ืื ื—ื ื• ืขื•ืจื›ื™ื ืคืจื•ืคื™ืœ ื—ื™ื‘ื•ืจ, ื”ื’ื“ืจืช ืงื‘ื•ืฆืช ืฉืจืชื™ Active Directory ื›ืฉืจืช ื”ืื™ืžื•ืช ื”ืจืืฉื™:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
4. ื›ืจื˜ื™ืกื™ื™ื” ืžืชืงื“ื -> ืื™ืžื•ืช ืื ื• ื’ื ื‘ื•ื—ืจื™ื ืืช ืงื‘ื•ืฆืช ื”ืฉืจืชื™ื ืฉืœ Active Directory:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
5. ื›ืจื˜ื™ืกื™ื™ื” ืžืชืงื“ื -> ืžืฉื ื™ ืื™ืžื•ืช, ื‘ื—ืจ ืืช ืงื‘ื•ืฆืช ื”ืฉืจืชื™ื ืฉื ื•ืฆืจื” ื‘ื” ืจืฉื•ื ืฉืจืช multiOTP. ืฉื™ื ืœื‘ ืฉืฉื ื”ืžืฉืชืžืฉ ื‘-Session ืขื•ื‘ืจ ื‘ื™ืจื•ืฉื” ืžืงื‘ื•ืฆืช ืฉืจืชื™ AAA ื”ืจืืฉื™ืช:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
ื”ื—ืœ ืืช ื”ื”ื’ื“ืจื•ืช ื•

ืฉืœื‘ 6, ื”ืœื ื”ื•ื ื”ืื—ืจื•ืŸ
ื‘ื•ืื• ื ื‘ื“ื•ืง ืื ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื•ื‘ื“ ืขื‘ื•ืจ SLL VPN:

ืขื‘ื•ืจ ืืœ 2FA (ืื™ืžื•ืช ื“ื•-ืฉืœื‘ื™ ืขื‘ื•ืจ ASA SSL VPN)
ื•ื•ืืœื”! ื‘ืขืช ื”ืชื—ื‘ืจื•ืช ื“ืจืš Cisco AnyConnect VPN Client, ืชืชื‘ืงืฉ ื’ื ืœื”ื–ื™ืŸ ืกื™ืกืžื” ืฉื ื™ื™ื” ื•ื—ื“ ืคืขืžื™ืช.

ืื ื™ ืžืงื•ื•ื” ืฉื”ืžืืžืจ ื”ื–ื” ื™ืขื–ื•ืจ ืœืžื™ืฉื”ื•, ื•ืฉื”ื•ื ื™ื™ืชืŸ ืœืžื™ืฉื”ื• ื—ื•ืžืจ ืœืžื—ืฉื‘ื” ืื™ืš ืœื”ืฉืชืžืฉ ื‘ื–ื”, ื—ื•ืคืฉื™ ืฉืจืช OTP, ืœืžืฉื™ืžื•ืช ืื—ืจื•ืช. ืฉืชืคื• ื‘ืชื’ื•ื‘ื•ืช ืื ืชืจืฆื•.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”