Skip to main content
prash001
New Member
August 8, 2026
Question

Moved from SSL vpn (radius) to IPSecV2 (SAML) - Could I do better

  • August 8, 2026
  • 3 replies
  • 50 views

Hi, we were an on-prem only company. Earlier this year we went hybrid with 365.

For VPN earlier we had our clients connecting through forticlient with AD credentials leveraging RADIUS. No MFA.

We then configured a parallel setup using IPSec ike v2 and authentication with EntraID, adding the MFA feature then.

My question is: is this the natural approach that most of the former on-premise companies adopt once moved to Cloud or are there other suggested setups, maybe leveraging already existent on-premise RADIUS infrastructure?
 

    3 replies

    ChrisWarne
    New Member
    August 8, 2026

    I would say what you’ve done is a pretty common approach when moving from a fully on-prem environment to a hybrid Microsoft 365 / Entra ID setup.

    A lot of organizations start moving VPN authentication toward Entra ID so they can use the same cloud identity, MFA, and Conditional Access policies they are already using for Microsoft 365.

    That said, there’s nothing wrong with continuing to use the existing RADIUS/NPS setup either. It can still be integrated with MFA and may make sense if you already have other systems depending on RADIUS.

    So in practice, it’s common to see both methods running in parallel for a while. You can keep the existing RADIUS-based VPN for legacy requirements while gradually moving users toward Entra ID + MFA.

    AEK
    SuperUser
    SuperUser
    August 9, 2026

    Hi Prash

    As said by Chris you did well.

    You definitely did it more secure than before, since you have now IPsec instead of SSL, and 2FA instead of password only.
    Regarding the auth source (RADIUS vs EntraID) it is up to you, but since you can do MFA with EntraID and (apparently) not with your RADIUS server then EntraID is better for security.

    AEK
    New Member
    August 10, 2026

    The move to IKEv2 with Entra ID and MFA sounds like a sensible step for a hybrid environment. It removes the dependency on the old RADIUS-only authentication while taking advantage of Entra ID and MFA.

    That said, I’d be interested to hear what others are doing in similar hybrid setups. Keeping RADIUS with MFA could still make sense in some environments, while Entra-based authentication may be simpler if the organization is already heavily invested in Microsoft 365.
     

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!