VPN and firewall 2FA (two-factor / two-step authentication) adds a second verification step on top of the password for SSL/IPsec VPN logins, the firewall admin panel and Windows sign-in / RDP logins. The goal is to block unauthorized access even if the password is stolen. SignLogger provides this second factor over RADIUS: the firewall or VPN sends a RADIUS request to SignLogger to verify the login; SignLogger authenticates the identity and then asks the user for a one-time code (TOTP) or an SMS code. If verification succeeds, access is granted. Because it is brand-independent, it works with any RADIUS-capable firewall/VPN without replacing your existing infrastructure. This protects remote access (VPN) and administrator sessions with a strong second factor managed from a single platform.
This page is for informational purposes; for setup details, see the product documentation.
Why is 2FA needed on VPN and firewall logins?
Remote access and admin panels are the doors attackers target most. Relying on the password alone is risky:
- Password leaks: Passwords stolen via phishing or breached password lists grant access on their own.
- Brute force: VPN and panel logins are exposed to automated guessing attacks.
- Privileged access: The firewall admin panel and VPN are critical doors into the whole network; a takeover causes major damage.
The second factor requires something the user has (an app on their phone or an SMS) even when the password is correct, so a stolen password alone is useless.
How does SignLogger VPN 2FA work?
SignLogger acts like a RADIUS server on your network and manages the second factor. The flow is:
- Request: The user signs in to the VPN or firewall panel with username and password. The device sends a RADIUS request to SignLogger to verify it.
- First factor: SignLogger authenticates the identity (local account or LDAP/Active Directory).
- Second factor: SignLogger asks the user for a one-time code; the user enters the code from their TOTP app or received by SMS.
- Decision: If the code is correct, RADIUS returns an "accept" response and access is granted; otherwise it is rejected.
- Record: Who was verified, when and on which login — all written to the audit log.
Which logins does it protect?
- SSL VPN and IPsec VPN: VPN logins for remote workers.
- Firewall admin panel: Firewall/security-appliance administrator sessions.
- Windows sign-in: A second factor for domain and local Windows sessions.
- RDP (remote desktop): 2FA on remote desktop connections.
Which verification methods does it support?
- TOTP (app-based): The 30-second one-time codes in apps such as Google Authenticator or Microsoft Authenticator — no internet required, the most secure method.
- SMS: A one-time code sent to the user's phone, via an SMS-provider integration.
Which firewalls and VPNs does it work with?
SignLogger 2FA is brand-independent and works with RADIUS-capable firewalls and VPNs: FortiGate, Palo Alto, SonicWall, WatchGuard, Zyxel, Cisco and others. You do not need to replace your existing hardware — you simply define SignLogger as the RADIUS server on your device. For step-by-step setup, see the SignLogger Firewall & VPN 2FA Setup Guide.
What does the SignLogger 2FA solution offer?
- Brand-independent RADIUS 2FA: With all RADIUS-capable firewalls/VPNs from a single platform.
- Central user management: Local accounts or LDAP/Active Directory integration; authorization by rules and groups (see Network Access Control (NAC)).
- Flexible methods: TOTP and SMS; per-user enrollment.
- Audit and reporting: Every verification event recorded.
- On your own infrastructure: Data stays within your organization.
Frequently Asked Questions
Are VPN 2FA and firewall panel 2FA the same solution?
Yes. Over RADIUS, SignLogger protects both SSL/IPsec VPN logins and firewall admin panel sessions (as well as Windows sign-in and RDP) with the same second-factor layer.
Which methods are used as the second factor?
TOTP (the one-time code in apps like Google/Microsoft Authenticator) and codes sent by SMS. TOTP is the most secure option because it requires no internet.
Do I need to replace my existing firewall?
No. The solution is brand-independent and works over RADIUS; on devices such as FortiGate, Palo Alto, SonicWall, WatchGuard, Zyxel or Cisco you simply define SignLogger as the RADIUS server.
Can I add 2FA to my Active Directory users?
Yes. SignLogger integrates with LDAP/Active Directory; you can add a second factor to your existing AD users on VPN and panel logins.
Does 2FA really protect if the password is stolen?
Yes. The second factor requires something the user has (an app/SMS on their phone). Even if the password is stolen, the attacker cannot access that one-time code and cannot log in.
Does it also work for Windows sign-in and RDP?
Yes. Besides VPN and the firewall panel, a second factor can be applied to Windows domain/local sign-in and RDP (remote desktop) logins.