We currently have ASA + DUO doing 2FA
Primary Authentication is handled by Cisco ISE
Secondary is done by DUO
User has an option to enter DUO Passcode in the second password filed he gets on Anyconnect or he can type Push
when user types Passcode 2FA...