Log into VPN with Duo Multi-Factor Authentication (MFA)

  1. Open the Cisco AnyConnect Secure Mobility Client from the Start Menu

  1. The login window will appear. If prompted, Enter "vpn2.cambriancollege.ca" in the text field then click the "Connect" button.

 

  1.  Select your group from the drop down menu, usually Cambrian_StaffUploaded Image (Thumbnail)
     
  2. Enter your Cambrian network credentials I.e “jqsmith” and click OK.

Note: This will default to a DUO Push to your mobile device. If you use an alternate DUO authentication method please see DUO Authentication Methods section near the end of the article for additional option.

  1. Depending on authentication method; approve the Duo request notification on your phone, answer the incoming phone call and press any key on the keypad, or provide the generated code from SMS, Duo Mobile App, or hardware token.

  1. If successful a message will confirm that the VPN has connected. Future connections will remember the server and group settings configured in the previous steps. The status will then change to Connected as shown below.

 

DUO Authentication Methods

If you do not use the DUO mobile app you can specify alternate methods by adding a comma (",") to the end of your password and append a Duo factor option:

A numeric passcode

Log in using a passcode, either generated with Duo Mobile, sent via SMS, generated by your hardware token, or provided by an administrator. Examples: "123456" or "2345678"

phone

Perform phone callback authentication.

sms

Send a new batch of SMS passcodes. Your authentication attempt will be denied. You can then authenticate with one of the newly-delivered passcodes. 

 

For example, if you wanted to use a passcode generated by a hardware token to authenticate, you would enter:

username: <USERNAME>
password: <YourPassword>,123456

For phone callback to authenticate, you would enter:

username: <USERNAME>
password: <YourPassword>,phone

*Note: in each case the password field is obfuscated, you will not be able to verify the keystrokes of your password and secondary authentication method.

You can also specify a number after the factor name if you have more than one device enrolled (as the automatic push or phone call goes to the first capable device attached to a user). So you can enter “phone2” or “push2” if you have two phones enrolled and you want the authentication request to go to the second phone.

To Disconnect

1. Right-Click the AnyConnect icon in the taskbar and select disconnect.

50% helpful - 2 reviews