SSL and Cisco Duo- Automatic Login
Issue: We enter in our username and password for SSL, we receive the Duo push, duo push stays for a few seconds, then passes/approves the connection without user intervention. This doesn't allow the user to allow or deny the connection thus rendering Duo useless.
Fortinet Users,
We currently are using LDAP to sync our FortiGate 400E. We then create a local firewall group on our 400E and tie the remote server (LDAP) to this group. Typically this is a group we have in AD already to match.
From here we tie this same group into the Authentication portal for SSL VPN connection.

Next, we set up the firewall policies to also use this group.

This process works without issues but now that we are trying to layer Cisco Duo on it we are having problems. What we did was add a radius to the firewall and then add an additional user to the remote group. We also had to make a NPS policy on our domain controller.
We then make sure the NPS policy is in place. Conditions include the windows group, Client IPv4 of the Duo server, PAP unencrypted to be allowed, and vender specific radius standard.


Does anyone know why this isn't working correctly? I feel this should be a simple configuration since it works without Duo.
Thanks,
Michael
