goauthentik / goauthentik/authentik

Integration of goauthentik 2FA with Cisco AnyConnect via Cisco ISE

Open
#15,460 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 1h
Merged PRs (30d)
644

Description

**Describe your question**
We currently use Cisco ISE for user authentication and enforcement of Dynamic Access Lists (DACLs) with Cisco AnyConnect VPN. Commercial 2FA/MFA solutions like Duo are commonly used to add a second authentication factor through Cisco ISE.

I’m interested in exploring if goauthentik can be integrated as a 2FA provider within this authentication flow. Specifically:

Can goauthentik act as a RADIUS or SAML identity provider that Cisco ISE can use to enforce 2FA for AnyConnect VPN connections?

What configuration steps are necessary on Cisco ISE and AnyConnect to support goauthentik as the 2FA source?

Are there any existing examples, best practices, or community guides for setting up goauthentik with Cisco ISE for VPN multi-factor authentication?

What potential challenges, limitations, or compatibility issues should be expected compared to commercial 2FA solutions like Duo?

This integration would allow organizations to leverage an open-source 2FA/MFA system with Cisco AnyConnect VPN authentication, possibly reducing licensing costs without sacrificing security.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.