TechKnowSurge
Cisco CCNA 5.1 Cisco CCNA 5.5 Cisco CCNA 5.8
VideoNetworkFree

MFA and DUO

VPNs protect network traffic in transit, but weak user credentials remain a major vulnerability — multi-factor authentication (MFA) through tools like Cisco Duo adds a critical second layer of verification to remote access connections.

Complete this video to capture a CTF flag worth 1 point.

About this video

VPNs are a foundational tool for keeping network traffic private and secure, whether through site-to-site configurations between office locations or remote access connections for individual users. In a site-to-site setup, routers or firewalls at each location exchange static configuration data, and security depends on keeping that configuration protected. Remote access VPNs introduce a different challenge — they rely on individual users authenticating with a username and password, and those credentials are frequently weak, reused, or exposed through phishing and data breaches. Multi-factor authentication (MFA) is the standard response to this problem. Rather than relying on a password alone, MFA requires users to verify their identity through two or more independent factors — typically something they know, such as a password; something they have, such as a mobile device; or something they are, such as a biometric. Requiring multiple factors means that a stolen password alone is not enough to gain access to the network. Cisco Duo is a widely adopted MFA solution that delivers this second factor through a smartphone app. When a user attempts to connect to the corporate network, they first submit their credentials as usual, and then Duo sends a push notification to their enrolled device. Depending on how the system is configured, the user either taps an approval button or enters a one-time code to complete authentication. Push notifications must be enabled on the device for the workflow to function smoothly, and the overall result is a substantially stronger authentication process that does not depend on users maintaining perfect password discipline.

What you'll learn

What's covered

MFA and Duo for VPN Security

Aligned to

Cisco CCNA
5.1 Define key security concepts
5.5 Describe IPsec remote access and site-to-site VPNs
5.8 Compare authentication, authorization, and accounting concepts

Key terms

Virtual Private Network
VPN
A technology that creates a secure, encrypted tunnel over a public network to protect data in transit.
Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Authentication
The process of verifying the identity of a user, device, or system.
Cisco Duo
A Cisco MFA application installed on a user's device that delivers authentication prompts, such as push notifications or one-time codes, to verify identity during network login.
Remote Access VPN
A VPN configuration that allows individual users to securely connect to a private network from a remote location.

Transcript

Why remote users need more than a password

VPN can help keep our information private and secure across public networks. However, if our end users aren't practicing good security techniques, then we're going to run into problems, and their account could be compromised — and now our network is compromised. One of the ways that we can counteract that is with MFA and Duo.

Typically, when we're connecting a site-to-site VPN, we have a router at each one of our sites, and we get on the router or firewall or whatever we're using here and we set it up to be a site-to-site VPN. There is static information that we're setting on both of these devices, and as long as that static information remains secure, then we're probably fairly good.

However, we have these remote users that also need to connect into the company network, and we need to make sure that that is secure as well. A lot of times what we'll have is we'll have it set up and prompt them for a username and password, and then they'll log into the network. However, usernames and passwords are pretty easily compromised nowadays, unless your users are practicing good password habits. So that's where we want to use something like MFA, multifactor authentication, to help solve that problem.

Multifactor authentication

Multifactor authentication, or MFA, is a way to combat a lot of users' inability to really manage their passwords well or have good password habits. MFA is this idea that there's multiple factors that you're authenticating against, and usually that is with something maybe you know, like a password; maybe it's something you have, like your phone or a password authentication software; and maybe something you are, like a finger or something. It could be any combination of these, but the idea is that it's multifactor, it's more than one. So you can't just have a password — maybe it's a password and also your phone.

Cisco Duo

Cisco actually has a solution for this, and it's Cisco Duo. Cisco Duo is an app that you can install on your phone, and then you use it for the authentication process as part of the multifactor authentication.

So when a user now goes to connect to a company's network, they first of all are going to have to provide their credentials. That's going to be passed, and then this company will then send a notification to the phone through this Duo app. It could pop up in a couple different ways. Number one, you have to go in there and get a little code that's on there and plug it in to make that connection. Or it could pop up with a little button that says, do you want to accept this type of connection. It just depends on how you set it up. Either way, you're going to want to have push notifications for the Duo app turned on on the phone, so that way you can be notified when you're connecting in.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →