goauthentik / goauthentik/authentik
Integration of goauthentik 2FA with Cisco AnyConnect via Cisco ISE
- Dominant language
- Python
- Stars
- 25.6k
- Forks
- 2k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 644
Description
**Describe your question**
We currently use Cisco ISE for user authentication and enforcement of Dynamic Access Lists (DACLs) with Cisco AnyConnect VPN. Commercial 2FA/MFA solutions like Duo are commonly used to add a second authentication factor through Cisco ISE.
I’m interested in exploring if goauthentik can be integrated as a 2FA provider within this authentication flow. Specifically:
Can goauthentik act as a RADIUS or SAML identity provider that Cisco ISE can use to enforce 2FA for AnyConnect VPN connections?
What configuration steps are necessary on Cisco ISE and AnyConnect to support goauthentik as the 2FA source?
Are there any existing examples, best practices, or community guides for setting up goauthentik with Cisco ISE for VPN multi-factor authentication?
What potential challenges, limitations, or compatibility issues should be expected compared to commercial 2FA solutions like Duo?
This integration would allow organizations to leverage an open-source 2FA/MFA system with Cisco AnyConnect VPN authentication, possibly reducing licensing costs without sacrificing security.
Contributor guide
Assessment
This issue has not been assessed yet.