cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
472
Views
0
Helpful
1
Replies

Auth Proxy Construct with multiple domains and sites

LarsG1
Level 1
Level 1

Hi Community,

I have a customer with multiple sites and domains. After a PoC, we are now in the process of planning the rollout across all sites. The remote sites are connected to the HQ via IPSec. Some sites have their own DC, the DC at HQ has all domains. All sites have SSL VPN (FortiGate) configured locally.

Now I am undecided on the best way to proceed in the planning.
However, the following thought has occurred to me:
The AD sync for the domains is configured at HQ. For a failure of the IPSec VPN, the DCs of the external sites are also deposited with their own AuthProxy. This is how I would create the failover security.
My question now is, if it works to store different DCs in the AD-Sync in the Admin Portal and to store the parameters (IKEY, SKEY, Api key) at several AuthProxys at different locations. I have actually not tried that yet.

1 Reply 1

DuoKristina
Cisco Employee
Cisco Employee

Yes, you can have multiple Authentication Proxy servers and domain controllers configured with Duo AD Sync for redundancy. See these Duo Knowledge Base articles for more information:

Duo, not DUO.
Quick Links