Secure Mobile Access 10.2 User Guide

DUO Security Authentication Support on Mobile Connect/Mobile Connect Clients

The SMA series supports DUO Security Authentication during user login. SMA appliances introduced the Capture Security Center (CSC) and DUO Security Authentication that was not compatible with the Capture Security Center (CSC) in Contemporary Mode. DUO Security Authentication login is now supported for different clients such as web browsers and Mobile Connect clients in both Contemporary and Classic Modes.

About DUO Authentication

DUO has several options for securing your authentication of users. Refer to information on the DUO website to determine which method works best for your SonicWall solution.

There are three main methods the receiver can use to authenticate with DUO :

  • DUO push: A prompt comes up on the screen from the DUO app that has been downloaded on the user’s mobile device.
  • Phone call: A call comes to the mobile device requesting the user to click one or more buttons to authenticate.
  • Passcode: A passcode comes by email or SMS/Text to the user’s mobile device, which the user then enters as part of the authentication process.

About RADIUS

RADIUS is a protocol or language SMA uses to authenticate users through the DUO authentication process. The SMA appliance uses RADIUS to communicate with the DUO authentication system.

Classic Mode

Configure SMA for multifactor authentication in Classic mode using the following steps

  1. Log in to the SMA appliance and navigate to Portals > Domains.

  2. Add a new domain by clicking Add Domain.

  3. Create a new RADIUS domain for DUO Authentication.

  4. Navigate to Portals > Portals and modify the default portal for duo authentication.

  5. On the General tab, select Display login message on custom login page to display custom login messages at login.

  6. Remove the default Login Message and paste in the “<script src="https://api-f74dbf3b.duosecurity.com/frame/hosted/Duo-SonicWall-SRA-v1.js"></script>” message.

  7. Access the user portal and choose DUO Authentication using the Radius credential for authentication.

  8. Choose an authentication method for DUO Authentication and proceed with the login.

  9. All three options, DUO Push, Call Me, or Passcode can be approved through a DUO application installed on a mobile device to proceed with the authentication.

    Creating an Offloaded Web Application Portal

    Log in to the user portal with DUO Authentication as the default user portal.

  10. Navigate to Portals > Portals after logging in to the appliance using the Admin portal.

  11. Click Offload Web Application to create an offloaded portal.

  12. Click Next. On the Server page, enter the Application Server Address along with options selected as shown here.

  13. Click Next twice. Remove the default Login Message and paste in the “<script src="https://api-f74dbf3b.duosecurity.com/frame/hosted/Duo-SonicWALL-SRA-v1.js"></script>” message.

  14. Edit the DUO Radius domain to associate it with the DUO offloaded portal.

  15. Edit the duo portal and paste the “<script src="https://api-f74dbf3b.duosecurity.com/frame/hosted/Duo-SonicWall-SRA-v1.js"></script>”duo security portal API configuration script into the Login Message field.

  16. Enable Display custom login page and select Display login message on custom login page.

  17. Access the offloaded portal (host entry is required if the DNS is not being used) and choose the duo authentication domain for duo authentication.

  18. DUO Push, Call Me, or Passcode can be approved from a duo application installed on a mobile device to proceed with the authentication.

  19. Ensure you have successfully accessed the offloaded portal with duo authentication.

Contemporary Mode

For Contemporary mode, administrators navigate to Portals > Portals and create a new portal by clicking Add Portal.Enable Display custom login page and ensure Display login message on custom login page is selected.

For Login Message, enter the DUO authentication script into the text input box. Script format: "<script src="https://api-f74dbf3b.duosecurity.com/frame/hosted/Duo-SonicWall-SRA-v1.js"></script>" as shown in the following figure.

Finish by creating a Radius domain.

Contemporary Mode with Web Browser Login

For Contemporary mode with a Web Browser Login, after setting up the DUO portal configuration, you can login to a portal with DUO authentication in Contemporary Mode with a web browser. Input a User Name and Password within a Radius domain. Prompt the DUO authentication page and select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. After completing the DUO authentication, you should be redirected back to the portal.

DUO Security Authentication with NetExtender Windows

For DUO Security Authentication with NetExtender Windows

  1. Open NetExtender and input a Server IP/Hostname, along with RADIUS authentication credentials Username, Password, and Domain name.

  2. Click Connect for NetExtender.
  3. Open the DUO Security Authentication page in your default browser. Select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. NetExtender returns an error message if all conditions are not met.

  4. DUO Push, Call Me, or Passcode can be approved from a duo application installed on a mobile device to proceed with the authentication.

  5. DUO Authentication is successful in the Windows NetExtender client.
  6. DUO Authentication fails in the Windows NetExtender client when the EPC check has failed.

  7. DUO Authentication fails in the Windows NetExtender client when a device is prohibited.

DUO Security Authentication with NetExtender Linux

For DUO Security Authentication with NetExtender Linux, input a User Name and Password. Click the Connect button for an SMA connection.

DUO Authentication with NetExtender in Ubuntu Linux with Device management enabled.

DUO Authentication with NetExtender successful in Ubuntu Linux.

Open the DUO Security Authentication page in your default browser. If using Firefox, the following is default user portal from Linux in Firefox with DUO Authentication.

Login and select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. Click Login. After completing the DUO authentication, you should be redirected back to the portal.

The following screen indicates successful DUO authentication with the user portal.

DUO Security Authentication with Mobile Connect for iOS

For DUO Security Authentication with Mobile Connect for iOS, click connect for an SMA connection. Input a User Name and Password. Open the DUO Security Authentication page as a WKWebview page in your default browser. Select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. WKWebview returns an error message if all conditions are not met.

DUO Security Authentication with Mobile Connect for macOS

For DUO Security Authentication with Mobile Connect for macOS, click connect for an SMA connection. Input a User Name and Password. Open the DUO Security Authentication page in your default browser. Select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. After completing the DUO authentication, you should be redirected back to the portal.

DUO Security Authentication with Mobile Connect for Android

For DUO Security Authentication with Mobile Connect for Android, click connect for an SMA connection. Input a User Name and Password. Open the DUO Security Authentication page in your default browser. Select one authentication method such as Send Me a Push, Call Me, or Enter a Passcode. Click Login. After completing the DUO authentication with Mobile Connect, you should be redirected back to the portal.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.