

(Optional) Configure a standard access list to be used for the split tunnel. You can refer to Certificate Enrollment for a PKI for more details on the certificate creation.Ĥ.

Create a Trustpoint in order to install the identity certificate, if not already present for local authentication. Configure the RADIUS server as aaa authentication and authorization as local.Īaa group server radius FlexVPN_auth_serverĪaa authentication login FlexVPN_auth group FlexVPN_auth_serverĪaa authorization network FlexVPN_authz localģ. The IP address of the RADIUS server must be the IP of the Duo Authentication Proxy.Īddress ipv4 10.197.243.97 auth-port 1812 acct-port 1813Ģ. Configuration Steps on C8000V (VPN Headend)ġ. In order to complete the configuration, take into consideration these sections. If successful, the An圜onnect connection is established.Duo authentication proxy receives the authentication response.The Duo service then authenticates the user, depending on the secondary authentication method (push, phone call, passcode).

