OpenVPN ToTP 2FA Using Untangle

Поделиться
HTML-код
  • Опубликовано: 30 янв 2025

Комментарии • 33

  • @MainelyElectrons
    @MainelyElectrons 3 года назад +5

    Awesome! Thanks for letting us know. Really appreciate your content both technical and business related

  • @Darkk6969
    @Darkk6969 3 года назад +3

    Very cool to have that in Untangle. I wonder if pfSense will have this in the future?

    • @Wilksey37
      @Wilksey37 3 года назад +1

      There is Google Authentication OTP in FreeRadius already on pfSense.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад +3

      They have it, but do not have a way right now to authorize it in the separate ToTP field. forum.netgate.com/topic/164678/openvpn-static-challenge-totp?_=1624625305372

  • @taras.morales
    @taras.morales 3 года назад

    That logo on the t-shirt, so alive!

  • @billhungerford5930
    @billhungerford5930 Год назад

    Lawrence, great video. Quick question: Can some of your openvpn untangle accounts be non MFA? In other words, can I create a second MFA account for each user and slowly bring them over? Terrified of cutting critical users off. I'd rather have each user deploy it and test it before I delete their original non MFA account.

  • @dougieshizzle
    @dougieshizzle 3 года назад +3

    What am I missing here? If I remove 'static-challenge "TOTP Code " 1' from my config file users only need username/password and brute forcing is possible. Shouldn't MFA be enforced server side? Also TOTP has been broken in the Linux Network Manager GUI for years.

    • @perryscopevids
      @perryscopevids 2 года назад

      Or if you use an Open VPN Client that does not appear to support the Static-challenge ( testing with OpenVPN for Android 0.7.33), you are not prompted for a ToTP code and can connect just fine with the username and password. MFA needs to be enforced server-side for this to add any security.

    • @dougieshizzle
      @dougieshizzle 2 года назад +1

      Latest Untangle update is enforcing TOTP server side. 👍🎊

  • @marciets1752
    @marciets1752 3 года назад

    Works great here

  • @anoork
    @anoork 3 года назад

    Same feature available in Opensens as well. AD+TOTP

  • @YK-ll4wt
    @YK-ll4wt 3 года назад

    More untangle videos please

  • @MrPDC-jr5yl
    @MrPDC-jr5yl 3 года назад

    Great video. Does untangle still offer free version? Cant find free download link anymore on their website!!!

  • @ne0dam
    @ne0dam 3 года назад

    It seems nice, but i'm wondering how all this handle the disconnect and auto-reconnect of the openvpnclient ?

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад

      You put in the 2FA each time

    • @MikeOxlong-
      @MikeOxlong- 3 года назад

      @@LAWRENCESYSTEMS ya that’s kinda useless and beyond terribly inconvenient, especially with mobile users on cellular networks where the users are in motion (aka vehicle) and run through dead zones in connectivity...
      I’d be more inclined to doing radius auth with a tightly controlled config, including limiting individual accounts to a single login and scripting limitations based of the clients connecting address, among other things internally for resource access such as no direct access to any resources other than via proxies connections (among other things)...

  • @derrysan
    @derrysan 3 года назад

    What hardware are you using for untangle? Can you share to us the links?
    Am looking for routers with supports for web filtering. Already using fortigate, they’re works great, but not for the pricelist.
    Thanks

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад

      When we deploy for clients we use there hardware.

  • @bykeauser1
    @bykeauser1 3 года назад

    Hi Lawrence your videos are nice. I need your help basicly i have openvpn server 2.5 version and it shows 2fa for web portal but when i connect the vpn it does not ask me for 2fa

  • @JayRocketBear
    @JayRocketBear 2 года назад

    Do you know if the TOTP + AD auth (ldap) is possible ? I mean not only using the local user repository

  • @techwithalext
    @techwithalext 3 года назад

    How did you download the ConnectWise Control client for Linux? I couldn't find the download for it.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  3 года назад +1

      The Connectwise Control server has a Java client that works in Linux.

  • @berndeckenfels
    @berndeckenfels 3 года назад

    Can untangle do reverse-proxy/port forwarding with TOTP for protecting Webapps without VPN as well (allow dynamic clients for some time to …). Can this be used as a general TOTP server/user database?

  • @kittysreview9055
    @kittysreview9055 3 года назад

    Wireguard Wireguard Wireguard

  • @sulaiman1515
    @sulaiman1515 3 года назад

    👍🤗

  • @TechySpeaking
    @TechySpeaking 3 года назад

    First