{"id":36872,"date":"2019-10-31T22:14:26","date_gmt":"2019-10-31T19:14:26","guid":{"rendered":"https:\/\/prohoster.info\/blog\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn\/"},"modified":"2019-10-31T22:14:26","modified_gmt":"2019-10-31T19:14:26","slug":"go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn","title":{"rendered":"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nevoja p\u00ebr t\u00eb ofruar qasje t\u00eb larg\u00ebt n\u00eb ambiente korporative po rritet gjithnj\u00eb e m\u00eb shum\u00eb, qoft\u00eb p\u00ebr p\u00ebrdoruesit e saj ose p\u00ebr partner\u00ebt q\u00eb kan\u00eb nevoj\u00eb p\u00ebr qasje n\u00eb nj\u00eb server t\u00eb caktuar n\u00eb organizat\u00ebn tuaj.<\/p>\n<p>P\u00ebr k\u00ebto q\u00ebllime, shumica e kompanive p\u00ebrdorin teknologjin\u00eb VPN, e cila ka provuar t\u00eb jet\u00eb nj\u00eb m\u00ebnyr\u00eb e sigurt p\u00ebr t\u00eb ofruar qasje n\u00eb burimet lokale t\u00eb organizat\u00ebs.<\/p>\n<p>Kompania ime nuk \u00ebsht\u00eb p\u00ebrjashtim, dhe ne gjithashtu, si shum\u00eb t\u00eb tjer\u00eb, p\u00ebrdorim k\u00ebt\u00eb teknologji. Dhe, si shum\u00eb t\u00eb tjer\u00eb, p\u00ebrdorim, si t\u00eb dh\u00ebn\u00ebs p\u00ebr qasje t\u00eb larg\u00ebt \u2014 Cisco ASA 55xx.<\/p>\n<p>Me rritjen e numrit t\u00eb p\u00ebrdoruesve t\u00eb larg\u00ebt, krijohet nevoja p\u00ebr t\u00eb leht\u00ebsuar procedur\u00ebn e l\u00ebshimit t\u00eb p\u00ebrllogaritjeve. Por n\u00eb t\u00eb nj\u00ebjt\u00ebn koh\u00eb, kjo duhet t\u00eb b\u00ebhet pa kompromis n\u00eb siguri.<\/p>\n<p>Ne gjet\u00ebm zgjidhjen n\u00eb aplikimin e autentifikimit me dy faktor\u00eb p\u00ebr lidhjen p\u00ebrmes Cisco SSL <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/vpn\/\"   title=\"VPN\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"48\">VPN<\/a>, duke p\u00ebrdorur fjal\u00ebkalimet nj\u00ebher\u00ebsh. Dhe ky publikim do t\u00eb tregoj\u00eb si t\u00eb organizoni nj\u00eb zgjidhje t\u00eb till\u00eb me nj\u00eb minimum kohor dhe pa kosto p\u00ebr softin e nevojsh\u00ebm (n\u00ebn kushtin q\u00eb Cisco ASA t\u00eb jet\u00eb tashm\u00eb n\u00eb infrastruktur\u00ebn tuaj).<\/p>\n<p>Mercati \u00ebsht\u00eb i mbushur me zgjidhje t\u00eb paketuar p\u00ebr gjenerimin e fjal\u00ebkalimeve nj\u00ebher\u00ebsh, nd\u00ebrsa ofron shum\u00eb mund\u00ebsi p\u00ebr marrjen e tyre, qoft\u00eb p\u00ebrmes d\u00ebrgimit t\u00eb fjal\u00ebkalimit p\u00ebrmes SMS ose p\u00ebrdorimit t\u00eb tokeneve, si ato \"fizike\" ashtu edhe ato programore (p\u00ebr shembull n\u00eb telefonin celular). Por d\u00ebshira p\u00ebr kursim dhe p\u00ebr t\u00eb ruajtur parat\u00eb p\u00ebr pun\u00ebdh\u00ebn\u00ebsin tim, n\u00eb kushtet e kriz\u00ebs aktuale m\u00eb detyroi t\u00eb gjej nj\u00eb m\u00ebnyr\u00eb falas p\u00ebr t\u00eb realizuar sh\u00ebrbimin e gjenerimit t\u00eb fjal\u00ebkalimeve nj\u00ebher\u00ebsh. I cili, p\u00ebrkund\u00ebr falas, paksa i n\u00ebnshtrohet zgjidhjeve komerciale (duhet theksuar q\u00eb ky produkt ka dhe nj\u00eb version komercial, por ne e kemi r\u00ebn\u00eb dakord se shpenzimet, n\u00eb para, do t\u00eb jen\u00eb zero).<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nPra, do t\u00eb na duhen:<\/p>\n<p> \u2014 Nj\u00eb imazh Linux me nj\u00eb set mjete t\u00eb integruara \u2014 multiOTP, FreeRADIUS dhe nginx, p\u00ebr qasje n\u00eb server p\u00ebrmes webit (http:\/\/download.multiotp.net\/ \u2014 un\u00eb p\u00ebrdora imazhin e gatsh\u00ebm p\u00ebr VMware)<br \/>\n \u2014 Nj\u00eb server Active Directory<br \/>\n \u2014 Vet\u00eb Cisco ASA (un\u00eb, p\u00ebr leht\u00ebsi, p\u00ebrdor ASDM)<br \/>\n \u2014 \u00c7do token softuerik q\u00eb mb\u00ebshtet mekanizmin TOTP (un\u00eb, p\u00ebr shembull, p\u00ebrdor Google Authenticator, por FreeOTP gjithashtu do t\u00eb funksiononte)<\/p>\n<p>Nuk do t\u00eb hyj n\u00eb detaje p\u00ebr zhvillimin e imazhit. N\u00eb dalje, do t\u00eb merrni Debian Linux me multiOTP dhe FreeRADIUS t\u00eb instaluara tashm\u00eb, t\u00eb konfiguruara p\u00ebr t\u00eb punuar s\u00eb bashku, si dhe nj\u00eb nd\u00ebrfaqe web p\u00ebr administrimin e OTP.<\/p>\n<p><b>Hapi 1. Iniciativ\u00eb e sistemit dhe konfiguroni p\u00ebr rrjetin tuaj<\/b><br \/>\nSistemka vjen me kredencialet root root. Mendoj se t\u00eb gjith\u00eb e kuptojn\u00eb se do t\u00eb ishte mir\u00eb t\u00eb ndryshohej fjal\u00ebkalimi i p\u00ebrdoruesit root pas login-it t\u00eb par\u00eb. \u00cbsht\u00eb gjithashtu e nevojshme t\u00eb ndryshohen cil\u00ebsimet e rrjetit (n\u00eb parazgjedhje kjo \u00ebsht\u00eb \u2018192.168.1.44\u2019 me gateway \u2018192.168.1.1\u2019). M\u00eb pas mund t\u00eb ribashkoni sistemin.<\/p>\n<p>N\u00eb Active Directory do t\u00eb krijojm\u00eb nj\u00eb p\u00ebrdorues <b>otp<\/b>, me fjal\u00ebkalimin <b>MySuperPassword<\/b>.<\/p>\n<p><b>Hapi 2. Konfiguroni lidhjen dhe importoni p\u00ebrdoruesit e Active Directory<\/b><br \/>\nP\u00ebr k\u00ebt\u00eb do t\u00eb na nevojitet akses n\u00eb konsol, si dhe skedari <b>multiotp.php<\/b>, duke p\u00ebrdorur t\u00eb cilin do t\u00eb konfigurojm\u00eb parametrat e lidhjes me Active Directory.<\/p>\n<p>Shkoni n\u00eb dosjen <i>\/usr\/local\/bin\/multiotp\/<\/i> dhe ekzekutojm\u00eb radhazi komandat e m\u00ebposhtme:<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config default-request-prefix-pin=0<\/code><\/pre>\n<p>\nP\u00ebrcakton n\u00ebse k\u00ebrkohet nj\u00eb PIN shtes\u00eb (i p\u00ebrhersh\u00ebm) gjat\u00eb hyrjes s\u00eb PIN-it t\u00eb p\u00ebrkohsh\u00ebm (0 ose 1)<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config default-request-ldap-pwd=0<\/code><\/pre>\n<p>\nP\u00ebrcakton n\u00ebse k\u00ebrkohet t\u00eb jepet fjal\u00ebkalimi i domain-it gjat\u00eb hyrjes s\u00eb PIN-it t\u00eb p\u00ebrkohsh\u00ebm (0 ose 1)<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-server-type=1<\/code><\/pre>\n<p>\nSpecifikon llojin e serverit LDAP (0 = server i zakonsh\u00ebm LDAP, n\u00eb rastin ton\u00eb 1 = Active Directory)<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-cn-identifier=\"sAMAccountName\"<\/code><\/pre>\n<p>\nSpecifikon se n\u00eb \u00e7far\u00eb forme duhet t\u00eb paraqitet emri i p\u00ebrdoruesit (kjo vler\u00eb do t\u00eb nxjerr\u00eb vet\u00ebm emrin, pa domain-in)<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-group-cn-identifier=\"sAMAccountName\"<\/code><\/pre>\n<p>\nE nj\u00ebjta gj\u00eb, vet\u00ebm p\u00ebr grupin<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-group-attribute=\"memberOf\"<\/code><\/pre>\n<p>\nSpecifikon metod\u00ebn e p\u00ebrcaktimit t\u00eb p\u00ebrkat\u00ebsis\u00eb s\u00eb p\u00ebrdoruesit n\u00eb grup<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-ssl=1<\/code><\/pre>\n<p>\nDuhet t\u00eb p\u00ebrdorim lidhje t\u00eb sigurt me serverin LDAP (sigurisht q\u00eb po!)<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-port=636<\/code><\/pre>\n<p>\nPorti p\u00ebr lidhjen me serverin LDAP<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-domain-controllers=adSRV.domain.local<\/code><\/pre>\n<p>\nAdresa e serverit tuaj Active Directory<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-base-dn=\"CN=Users,DC=domain,DC=local\"<\/code><\/pre>\n<p>\nSpecifikojm\u00eb nga ku t\u00eb fillojm\u00eb k\u00ebrkimin e p\u00ebrdoruesve n\u00eb domain<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-bind-dn=\"otp@domain.local\"<\/code><\/pre>\n<p>\nSpecifikojm\u00eb nj\u00eb p\u00ebrdorues q\u00eb ka t\u00eb drejtat p\u00ebr t\u00eb k\u00ebrkuar n\u00eb Active Directory<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config ldap-server-password=\"MySuperPassword\"<\/code><\/pre>\n<p>\nSpecifikojm\u00eb fjal\u00ebkalimin e p\u00ebrdoruesit p\u00ebr lidhjen me Active Directory<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-network-timeout=10<\/code><\/pre>\n<p>\nNe caktojm\u00eb nj\u00eb koh\u00eb p\u00ebr lidhjen me Active Directory<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-time-limit=30<\/code><\/pre>\n<p>\nNe caktojm\u00eb nj\u00eb kufizim n\u00eb koh\u00eb p\u00ebr operacionin e importit t\u00eb p\u00ebrdoruesve<\/p>\n<pre><code class=\"bash\">.\/multiotp.php -config ldap-activated=1<\/code><\/pre>\n<p>\nAktivojm\u00eb konfigurimin e lidhjes me Active Directory<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -debug -display-log -ldap-users-sync<\/code><\/pre>\n<p>\nB\u00ebjm\u00eb importimin e p\u00ebrdoruesve nga Active Directory<\/p>\n<p><b>Hapi 3. Generojm\u00eb QR-kod p\u00ebr tokenin<\/b><br \/>\nK\u00ebtu gjith\u00e7ka \u00ebsht\u00eb shum\u00eb e thjesht\u00eb. Hapni nd\u00ebrfaqen web t\u00eb serverit OTP n\u00eb shfletues, identifikohuni (mos harroni t\u00eb ndryshoni fjal\u00ebkalimin p\u00ebr adminin, i cili \u00ebsht\u00eb vendosur si i paracaktuar!), dhe klikoni butonin \u00abPrint\u00bb:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/61d02cc45c45a5d35cd555ae460a9aed.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nSi rezultat i k\u00ebtij veprimi do t\u00eb shfaqet nj\u00eb faqe, ku p\u00ebrmbahen dy QR-kod. Ne e injorojm\u00eb me leht\u00ebsi t\u00eb parin (pavar\u00ebsisht nga shkrimi t\u00ebrheq\u00ebs Google Authenticator \/ Authenticator \/ 2 Steps Authenticator) dhe p\u00ebrs\u00ebri me leht\u00ebsi skanojm\u00eb kodin e dyt\u00eb me tokenin softuerik n\u00eb telefon:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/19b6d39be7791fa76e31e9add8ca8a47.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n(po, un\u00eb e prisha q\u00ebllimisht QR-kodet q\u00eb ta b\u00ebj at\u00eb t\u00eb pap\u00ebrdorsh\u00ebm).<\/p>\n<p>Pas k\u00ebtyre veprimeve, n\u00eb aplikacionin tuaj, \u00e7do tridhjet\u00eb sekonda do t\u00eb filloj\u00eb t\u00eb gjenerohet nj\u00eb fjal\u00ebkalim me gjasht\u00eb shifra.<\/p>\n<p>P\u00ebr siguri, mund t\u00eb kryeni nj\u00eb verifikim n\u00eb t\u00eb nj\u00ebjt\u00ebn nd\u00ebrfaqe:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/f3a848c90914ba3954f4ecdcd20f4505.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nDuke futur emrin e p\u00ebrdoruesit dhe fjal\u00ebkalimin e p\u00ebrkohsh\u00ebm nga aplikacioni n\u00eb telefon. Marr\u00eb p\u00ebrgjigje pozitive? At\u00ebher\u00eb kalojm\u00eb p\u00ebrpara.<\/p>\n<p><b>Hapi 4. Rregullojm\u00eb dhe testojm\u00eb funksionimin e FreeRADIUS<\/b><br \/>\nSi\u00e7 e p\u00ebrmenda m\u00eb sip\u00ebr \u2014 multiOTP \u00ebsht\u00eb tashm\u00eb i konfiguruar p\u00ebr t\u00eb punuar me FreeRADIUS, ne vet\u00ebm duhet t\u00eb kryejm\u00eb teste dhe t\u00eb shtojm\u00eb n\u00eb skedarin e konfigurimit t\u00eb FreeRADIUS informacionin p\u00ebr portin ton\u00eb VPN.<\/p>\n<p>Kthehemi n\u00eb konsol\u00ebn e serverit, n\u00eb direktorin\u00eb <i>\/usr\/local\/bin\/multiotp\/<\/i>, shkruajm\u00eb:<\/p>\n<pre><code class=\"bash\">.\\\/multiotp.php -config debug=1\\n.\\\/multiotp.php -config display-log=1<\/code><\/pre>\n<p>\nDuke aktivizuar k\u00ebshtu regjistrimin m\u00eb t\u00eb detajuar.<\/p>\n<p>N\u00eb skedarin e konfigurimit t\u00eb klient\u00ebve FreeRADIUS (<i>\/etc\/freeradius\/clinets.conf<\/i>) komentojm\u00eb t\u00eb gjitha rreshtat q\u00eb lidhen me <b>localhost<\/b> dhe shtojm\u00eb dy regjistra:<\/p>\n<pre><code class=\"bash\">client localhost {\\n        ipaddr = 127.0.0.1\\n        secret          = testing321\\n        require_message_authenticator = no\\n}<\/code><\/pre>\n<p>\n \u2014 p\u00ebr testim<\/p>\n<pre><code class=\"bash\">client 192.168.1.254\\\/32 {\\n        shortname =     CiscoASA\\n        secret =        ConnectToRADIUSSecret\\n}<\/code><\/pre>\n<p>\n \u2014 p\u00ebr portin ton\u00eb VPN.<\/p>\n<p>Rinisni FreeRADIUS dhe provoni t\u00eb identifikoheni:<\/p>\n<pre><code class=\"bash\">radtest username 100110 localhost 1812 testing321<\/code><\/pre>\n<p>\nku <i>username <\/i>= emri i p\u00ebrdoruesit, <i>100110 <\/i>= fjal\u00ebkalimi, i l\u00ebshuar nga aplikacioni n\u00eb telefon, <i>localhost <\/i>= adresa e serverit RADIUS, <i>1812 <\/i> \u2014 porta e serverit RADIUS, <i>testing321 <\/i> \u2014 fjal\u00ebkalimi i klientit t\u00eb serverit RADIUS (q\u00eb e kemi caktuar n\u00eb konfigurim).<\/p>\n<p>Rezultati i k\u00ebtij komande do t\u00eb jet\u00eb nj\u00eb dalje, dikur e till\u00eb:<\/p>\n<pre><code class=\"bash\">D\u00ebrgimi i Access-Request me id 44 n\u00eb 127.0.0.1 port 1812\n        User-Name = \"username\"\n        User-Password = \"100110\"\n        NAS-IP-Address = 127.0.1.1\n        NAS-Port = 1812\n        Message-Authenticator = 0x00000000000000000000000000000000\nrad_recv: Access-Accept paket nga host 127.0.0.1 port 1812, id=44, gjat\u00ebsi=20<\/code><\/pre>\n<p>\nTani tani kemi nevoj\u00eb t\u00eb sigurohemi q\u00eb p\u00ebrdoruesi ka kaluar me sukses autentifikimin. P\u00ebr k\u00ebt\u00eb, ne do t\u00eb shikojm\u00eb n\u00eb logun e multiotp:<\/p>\n<pre><code class=\"bash\">tail \/var\/log\/multiotp\/multiotp.log<\/code><\/pre>\n<p>\nDhe n\u00ebse sh\u00ebnimi i fundit atje do t\u00eb jet\u00eb:<\/p>\n<pre><code class=\"bash\">2016-09-01 08:58:17     notice  username  P\u00ebrdorues    OK: P\u00ebrdoruesi username u identifikua me sukses nga 127.0.0.1\n2016-09-01 08:58:17     debug           Debug   Debug: 0 OK: Token i pranuar nga 127.0.0.1<\/code><\/pre>\n<p>\nAtyre gjith\u00e7ka ka shkuar mir\u00eb dhe ne mund t\u00eb vazhdojm\u00eb me<\/p>\n<p><b>Hapi 5. Konfigurimi i Cisco ASA<\/b><br \/>\nT\u00eb dakordohemi q\u00eb ne tashm\u00eb kemi nj\u00eb grup t\u00eb konfigurur dhe politika p\u00ebr qasje p\u00ebr SSL VPN, t\u00eb konfiguruar n\u00eb lidhje me Active Directory, dhe na nevojitet t\u00eb shtojm\u00eb autentifikimin me dy faktor\u00eb p\u00ebr k\u00ebt\u00eb profil.<\/p>\n<p><strong>1.<\/strong> Shtojm\u00eb nj\u00eb grup t\u00eb ri <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/\"   title=\"server\u00ebsh\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1345\">server\u00ebsh<\/a> AAA:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/2151921d562b59860813899504823a51.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<strong>2.<\/strong> Shtojm\u00eb n\u00eb grup serverin ton\u00eb multiOTP:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/29017af257fee5de4dcc4f61a7715a66.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<strong>3.<\/strong> Korrigjojm\u00eb <b>profilin e lidhjes<\/b>, duke caktuar si serverin kryesor t\u00eb autentifikimit grupin e server\u00ebve t\u00eb Active Directory:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/5bc1c8ecdecf2c11b67d169efc459ad3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<strong>4.<\/strong> N\u00eb sked\u00ebn <b>Advanced -&gt; Authentification<\/b> po ashtu zgjedhim grupin e server\u00ebve t\u00eb Active Directory:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/20642ed92fa047013beb72eadcfc42f3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<strong>5.<\/strong> N\u00eb sked\u00ebn <b>Advanced -&gt; Secondary<\/b> n\u00eb autentifikimin zgjedhim grupin e krijuar t\u00eb server\u00ebve, n\u00eb t\u00eb cilin \u00ebsht\u00eb shkruar serveri multiOTP. E theksojm\u00eb se emri i sesionit t\u00eb p\u00ebrdoruesit trash\u00ebgohet nga grupi primar i server\u00ebve AAA:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/c132c7f8456182de0c483205d713f75a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nShkojm\u00eb p\u00ebrpara me konfigurimet dhe<\/p>\n<p><b>Hapi 6, q\u00eb \u00ebsht\u00eb edhe i fundit<\/b><br \/>\nKontrollojm\u00eb n\u00ebse kemi autentifikimin me dy faktor\u00eb p\u00ebr SSL VPN:<\/p>\n<p><img decoding=\"async\" alt=\"Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN)\" src=\"\/wp-content\/uploads\/2019\/08\/72d90615b46bf13c81c289d4efddc840.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nVua-la! Gjat\u00eb lidhjes p\u00ebrmes Cisco AnyConnect VPN Client gjithashtu do t\u00eb k\u00ebrkohet nj\u00eb fjal\u00ebkalim i dyt\u00eb, nj\u00eb her\u00ebsh.<\/p>\n<p>Shpresoj se ky artikull do t'i ndihmoj\u00eb dikujt dhe se do t'i jap\u00eb dikujt mund\u00ebsi p\u00ebr t\u00eb reflektuar mbi se si mund t\u00eb p\u00ebrdorin k\u00ebt\u00eb, <b>t\u00eb lir\u00eb<\/b> server OTP, p\u00ebr detyra t\u00eb tjera. Ndani n\u00eb komente, n\u00ebse do t\u00eb keni d\u00ebshir\u00eb.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/308988\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0442\u0440\u0435\u0431\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u0435\u0442 \u0432\u0441\u0435 \u0447\u0430\u0449\u0435 \u0438 \u0447\u0430\u0449\u0435, \u043d\u0435 \u0432\u0430\u0436\u043d\u043e, \u0431\u0443\u0434\u044c \u0442\u043e \u0441\u0432\u043e\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u043b\u0438 \u043f\u0430\u0440\u0442\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0442\u043e\u043c\u0443 \u0438\u043b\u0438 \u0438\u043d\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0432 \u0432\u0430\u0448\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438. \u0414\u043b\u044f \u044d\u0442\u0438\u0445 \u0446\u0435\u043b\u0435\u0439, \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044e VPN, \u0437\u0430\u0440\u0435\u043a\u043e\u043c\u0435\u043d\u0434\u043e\u0432\u0430\u0432\u0448\u0443\u044e \u0441\u0435\u0431\u044f, \u043a\u0430\u043a \u043d\u0430\u0434\u0435\u0436\u043d\u043e \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u044b\u0439 \u0441\u043f\u043e\u0441\u043e\u0431 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u044b\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438. \u041c\u043e\u044f \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f \u043d\u0435 \u0441\u0442\u0430\u043b\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27626,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-36872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0442\u0440\u0435\u0431\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u0435\u0442 \u0432\u0441\u0435 \u0447\u0430\u0449\u0435 \u0438 \u0447\u0430\u0449\u0435, \u043d\u0435 \u0432\u0430\u0436\u043d\u043e, \u0431\u0443\u0434\u044c \u0442\u043e \u0441\u0432\u043e\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u043b\u0438 \u043f\u0430\u0440\u0442\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0442\u043e\u043c\u0443 \u0438\u043b\u0438 \u0438\u043d\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0432 \u0432\u0430\u0448\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438..\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Go to 2FA (\u0414\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0430\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u0434\u043b\u044f ASA SSL VPN) | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0442\u0440\u0435\u0431\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u0435\u0442 \u0432\u0441\u0435 \u0447\u0430\u0449\u0435 \u0438 \u0447\u0430\u0449\u0435, \u043d\u0435 \u0432\u0430\u0436\u043d\u043e, \u0431\u0443\u0434\u044c \u0442\u043e \u0441\u0432\u043e\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u043b\u0438 \u043f\u0430\u0440\u0442\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0442\u043e\u043c\u0443 \u0438\u043b\u0438 \u0438\u043d\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0432 \u0432\u0430\u0448\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438..\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Shkoni te 2FA (Autentifikimi me dy faktor\u00eb p\u00ebr ASA SSL VPN) | ProHoster","description":"Nevojat p\u00ebr t\u00eb ofruar qasje remote n\u00eb mjedisin korporativ po rriten gjithnj\u00eb e m\u00eb shum\u00eb, pa dallim n\u00ebse jan\u00eb p\u00ebrdoruesit tan\u00eb apo partner\u00ebt, t\u00eb cil\u00ebve u nevojitet qasje n\u00eb nj\u00eb server t\u00eb caktuar n\u00eb organizat\u00ebn tuaj..","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Go to 2FA (\u0414\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u0430\u044f \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u044f \u0434\u043b\u044f ASA SSL VPN) | ProHoster","og:description":"\u041f\u043e\u0442\u0440\u0435\u0431\u043d\u043e\u0441\u0442\u044c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0443\u0434\u0430\u043b\u0435\u043d\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u0435\u0442 \u0432\u0441\u0435 \u0447\u0430\u0449\u0435 \u0438 \u0447\u0430\u0449\u0435, \u043d\u0435 \u0432\u0430\u0436\u043d\u043e, \u0431\u0443\u0434\u044c \u0442\u043e \u0441\u0432\u043e\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u043b\u0438 \u043f\u0430\u0440\u0442\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0442\u043e\u043c\u0443 \u0438\u043b\u0438 \u0438\u043d\u043e\u043c\u0443 \u0441\u0435\u0440\u0432\u0435\u0440\u0443 \u0432 \u0432\u0430\u0448\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438..","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/go-to-2fa-dvuhfaktornaya-autentifikatsiya-dlya-asa-ssl-vpn","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:14:26+00:00","article:modified_time":"2019-10-31T19:14:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36872","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 17:05:56","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:37:23","updated":"2026-02-09 17:05:56","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=36872"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36872\/revisions"}],"predecessor-version":[{"id":158589,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36872\/revisions\/158589"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/27626"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=36872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=36872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=36872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}