Firebox Mobile VPN with IKEv2 Integration with AuthPoint for Microsoft Entra ID Users

Deployment Overview

This document describes how to set up AuthPoint multi-factor authentication (MFA) for Microsoft Entra ID users that use Mobile VPN with IKEv2. Your Firebox must run Fireware v12.10.4 or higher to authenticate Microsoft Entra ID users with the AuthPoint authentication server.

This integration guide is for the Firebox. To configure MFA for Microsoft Entra ID users that use Mobile VPN with IKEv2 with Firebox Cloud, go to Firebox Cloud Mobile VPN with IKEv2 Integration with AuthPoint for Microsoft Entra ID Users.

To configure AuthPoint MFA for Active Directory users that use Mobile VPN with IKEv2, go to Firebox Mobile VPN with IKEv2 Integration with AuthPoint for Active Directory Users.

Your WatchGuard Firebox must already be deployed and configured before you set up MFA with AuthPoint.

For MSCHAPv2 connections, group membership comes from the NPS filter-ID (attribute 11) value, not from AuthPoint.

Contents

Integration Summary

The hardware and software used in this guide include:

  • Firebox with Fireware v12.10.4 or higher
  • Windows Server with Microsoft Network Policy Server (NPS) deployed in Azure

WatchGuard Firebox Authentication Data Flow with AuthPoint

AuthPoint communicates with various cloud-based services and service providers. This diagram shows the data flow of an MFA transaction for a WatchGuard Firebox.

Topology diagram

Before You Begin

Before you begin these procedures, make sure that you have deployed the required components in Microsoft Azure. For this integration, Network Policy Server (NPS) must run on a Windows Server virtual machine in Azure and be joined Microsoft Entra Domain Services. This guide does not use an on-premises NPS server.

Make sure that:

  • You have a Microsoft Entra ID global administrator account
  • You have an active Azure subscription
  • You have installed and configured Microsoft Entra Domain Services in Azure
  • You have deployed a Windows Server virtual machine in Azure and installed Network Policy and Access Services, which includes Network Policy Server (NPS)
  • You have joined the Windows Server virtual machine that runs NPS to your Microsoft Entra Domain Services managed domain
  • A token is assigned to a user in AuthPoint
  • You have registered and connected your Firebox to WatchGuard Cloud as a locally-managed Firebox or a cloud-managed Firebox (go to Add a Locally-Managed Firebox to WatchGuard Cloud and Add a Cloud-Managed Firebox to WatchGuard Cloud)

Mobile VPN with IKEv2 does not support OTP authentication. If you have to use OTP authentication, such as with a hardware token, we recommend that you configure AuthPoint MFA for Mobile VPN with SSL.

Additional charges might apply for the use of Microsoft Azure. To learn more about Microsoft Azure, go to What is Microsoft Entra Domain Services.