SonicOS 8 IPSec VPN

Table of Contents

Two-Factor Authentication (2-FA) for Global VPN Client

SonicOS supports two-factor authentication (2-FA) for IPSec Group VPN connections using the SonicWall Global VPN Client (GVC). This feature adds a second layer of authentication—either a Time-Based One-Time Password (TOTP) or a One-Time Password (OTP) delivered via email—to the standard username and password credentials, mitigating the risk of unauthorized access through compromised credentials.

The minimum required GVC version is 5.0 or later.

The 2-FA for GVC is configured by enabling the one-time password method on the user group referenced by the Group VPN policy.

Two-factor authentication for GVC uses the same configuration workflows and settings used for SSL VPN two-factor authentication.The 2FA token is bound to the user account. If a user is configured for both SSL VPN and GVC access, the same TOTP enrollment or OTP method applies to both connection types.

To configure 2FA for GV

  1. Navigate to DEVICE | Users > Local Users & Groups.
  2. Click Local Groups and select the user group referenced by the Group VPN policy (for example, Trusted Users).
  3. Click Edit.
  4. On the Local Group Settings, under One-time password method drop-down, select one of the following:
    1. OTP via Mail — Sends a one-time code to the user's configured email address at each login.
    2. TOTP — Requires users to enroll a TOTP authenticator app and provide a time-based code at each login.

  5. Click Save.