A VPN is critical technology for providing secure remote access to corporate resources. Unfortunately, it is an equally attractive target for attackers. A stolen or guessed VPN password is a door that opens directly onto your internal network.
The solution: make VPN authentication two-factor (2FA). With SignLogger, this is possible without any additional hardware or a separate license.
SignLogger 2FA SSL VPN Architecture
SignLogger communicates with your firewall over the RADIUS protocol:
- The user enters a username and password in the VPN client.
- The firewall forwards those credentials to SignLogger in a RADIUS request.
- SignLogger validates the password (against Active Directory).
- SignLogger then also requires a second factor (TOTP, SMS or push).
- If both succeed, an "Access-Accept" response is returned to the firewall and the VPN tunnel is established.
Supported Firewall Brands
- FortiGate: SSL VPN and the management portal — ready for third-party RADIUS.
- Cisco ASA / Firepower: AnyConnect VPN and ASDM admin login.
- Sophos XG / XGS: the SSL VPN portal.
- Palo Alto: GlobalProtect.
- SonicWall: NetExtender VPN.
- WatchGuard: Mobile VPN with SSL.
- Check Point: Mobile Access Portal.
This list keeps growing — in principle, any device that supports RADIUS is compatible.
Second-Factor Options
- TOTP: compatible with Google Authenticator, Microsoft Authenticator and Authy, based on the RFC 6238 standard.
- SMS: a one-time code sent to the registered mobile number. Ideal for offline users.
- Push notification: an "Approve / Deny" flow through the mobile app.
- Backup codes: emergency codes for use without an internet connection.
2FA for the Firewall Management Interface
Beyond SSL VPN, firewall administrator logins (the admin web interface, the SSH console) can also be protected with SignLogger 2FA. Even if an attacker obtains the admin password, they cannot log in without the physical second factor.
Compliance: ISO 27001, SOC 2, PCI DSS and KVKK
Most compliance standards mandate 2FA for access to critical systems:
- ISO 27001 A.9.4.2: secure log-on procedures
- PCI DSS Req. 8.4: MFA required for access to cardholder data
- NIST SP 800-63B: AAL2 and above require 2FA
- KVKK (Law No. 6698), Art. 12: 2FA as part of adequate security measures
Quick Setup
A typical FortiGate deployment:
- Enable the RADIUS Server module in SignLogger.
- In the user directory, assign a 2FA method (TOTP or SMS) to each user.
- On the FortiGate, add SignLogger's IP address as a RADIUS server.
- Switch the SSL VPN authentication method to RADIUS.
- On their first login, users scan a QR code with the mobile app to activate TOTP.
Time to complete: less than one hour.
Request a demo or ask our technical team for detailed setup assistance.