2 August 2018 / cisco AnyConnect VPN with(out) DUO 2FA. A user's status can be set as Bypass in the Duo Admin Panel (to bypass 2FA). If you connect via the Cisco AnyConnect VPN client, you will need to type the new “sslvpn.asu.edu/2fa” address into the field, like below, before clicking on “Connect”. To use SSLVPN to have a dedicated tunnel for all traffic from you laptop back through the ASU SSLVPN, for example in the special case you are traveling in China, use. The purpose of this document is to enable Rublon Two-Factor Authentication (2FA) for users logging in to Cisco AnyConnect VPN with ASA. In order to achieve that using LDAP (e.g. FreeIPA, OpenLDAP, Microsoft Active Directory), you have to use Rublon Access Gateway. All required steps will be described in this document. Microsoft Word - Using CSE Cisco Anyconnect with 2FA.docx Author: Barbara Einfalt Created Date: 5/12/2015 12:02:08 PM.
Skip to end of metadataGo to start of metadata
Download Cisco AnyConnect VPN
- Log into theUW VPN website, login with your WatIAM user ID credentials, and enter your 2FA method in the 2nd Password field:
- Duo Mobile Push: type in 'push'
- Duo Mobile Call: type in 'phone'
- Duo hardware token or Duo app:enter your 6-digit code
- For Duo Bypass code:enter your bypass code
- For Yubikey:enter the code generated by touching the Yubikey
- Click the installation for your operating system, in this case, Download for Windows
- When downloading, click the arrow beside the download and click Open orOpen when done
- Cisco AnyConnect Secure Mobility Client Setuppop up will appear
- ClickNext
- Click I agree to the terms in the License Agreement
- Click Next
- Click Install
- Once installation is complete, click Finish
Use Cisco AnyConnect VPN



Cisco Anyconnect 2fa Download
- Once it is installed, click theStartbutton to search for it and use it
- Specify the VPN server: cn-vpn.uwaterloo.ca
- Click Connect
- In the Group drop down select UW-General-Campus
- Enter your WatIAM user ID credentials (e.g., lgchase) and your 2FA method in the 2nd Password field:
- Duo Mobile Push: type in 'push'
- Duo Mobile Call: type in 'phone'
- Duo hardware token or Duo app:enter your 6-digit code
- For Duo Bypass code:enter your bypass code
- For Yubikey:enter the code generated by touching the Yubikey
- Click OK
- You should now be connected, you can double-check that you are by:
- Click the up arrow in your task bars right side to show hidden icons
- Hover over Cisco Anyconnect's icon to see if you are connected
Download Cisco AnyConnect VPN
- Go to theUW VPN website, login with your WatIAM user ID credentials and enter your 2FA method in the 2nd Password field:
- Duo Mobile Push: type in 'push'
- Duo Mobile Call: type in 'phone'
- Duo hardware token or Duo app:enter your 6-digit code
- For Duo Bypass code:enter your bypass code
- For Yubikey:enter the code generated by touching the Yubikey
- Click the installation for your operating system, in this case, Download for MacOS
- Double-click the package downloaded to run the installer
- AnyConnect Secure Mobility Client window will pop up to install package and will require you to accept the Cisco software license
- Click Finish
Use Cisco AnyConnect VPN
- Open Cisco AnyConnect
- Specify the VPN server: cn-vpn.uwaterloo.ca
- Click Connect
- In the Group drop down select UW-General-Campus
- Enter your WatIAM user ID credentials (e.g., lgchase) and your 2FA method in the 2nd Password field:
- Duo Mobile Push: type in 'push'
- Duo Mobile Call: type in 'phone'
- Duo hardware token or Duo app:enter your 6-digit code
- For Duo Bypass code:enter your bypass code
- For Yubikey:enter the code generated by touching the Yubikey
- Click OK
- When the client is active, the VPN connection can be controlled from the Menu Bar icon:
Related articles
Cisco Anyconnect Multi Factor Authentication

Cisco 2 Factor Authentication
