cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
402
Views
0
Helpful
1
Replies

Yubikey for VPN connection

ShelBytes
Level 1
Level 1

Hello,

I'd like to know if we can use an yubikey for a VPN connection ? As we can do for a RDP connection.

Thanks !

1 Reply 1

DuoKristina
Cisco Employee
Cisco Employee

Yes, if you are using a YubiKey to generate passcodes for Duo Windows Logon you can also use the YubiKey passcode to log into a Duo-protected VPN.

If your VPN is configured with the Duo Authentication Proxy and RADIUS or LDAP then you can append the YubiKey OTP to the submitted password after a delimiter character (default is a comma), like password,cccccciduegtucgnufcccghdjcndfoovvgrgekjiglef

If your VPN's Duo configuration shows the Duo MFA prompt in a browser (like if you have set your VPN up with Duo SSO), then you would select the YubiKey token option in Universal Prompt or use the "Enter a passcode" field in traditional Duo Prompt and tap the YubiKey to generate the passcode.

You also have the option of using a FIDO2-compatible YubiKey as a WebAuthn roaming authenticator (security key) in the browser-based Duo prompt, but not for RADIUS/LDAP.

Duo, not DUO.
Quick Links