Firebox Cloud Mobile VPN with IKEv2 Integration with AuthPoint for Microsoft Entra ID Users

Deployment Overview

This document describes how to set up AuthPoint multi-factor authentication (MFA) for Microsoft Entra ID users that use Mobile VPN with IKEv2. This integration guide is specific to the Firebox Cloud.

Your WatchGuard Firebox Cloud must already be configured and deployed before you set up MFA with AuthPoint. For detailed steps on how to deploy WatchGuard Firebox Cloud on Azure, see Deploy Firebox Cloud on Microsoft Azure.

Contents

Integration Summary

The hardware and software used in this guide include:

  • Firebox Cloud with Fireware v12.7.1 or higher
  • Firebox Cloud with Fireware v12.7 and lower
  • AuthPoint Gateway v7.3.0 or higher
  • Windows Server 2019 with Microsoft Network Policy Server (NPS)

Before You Begin

Before you begin these procedures, make sure that:

  • You have a Microsoft Entra ID global administrator account
  • You have an active Azure subscription
  • You have installed and configured Microsoft Entra Domain Services
  • You have installed Network Policy and Access Services, which includes Network Policy Server (NPS)
  • You have joined NPS to your Microsoft Entra Domain Services managed domain
  • You have a WatchGuard Firebox Cloud deployed on Azure (see Deploy Firebox Cloud on Microsoft Azure)
  • If your Firebox Cloud runs Fireware v12.7.1 or higher, you must register and connect your Firebox Cloud to WatchGuard Cloud as a locally-managed Firebox or a cloud-managed Firebox (see Add a Locally-Managed Firebox to WatchGuard Cloud and Add a Cloud-Managed Firebox to WatchGuard Cloud)
  • If your Firebox Cloud runs Fireware Fireware v12.7 and lower, you must install and configure v7.3.0 or higher of the AuthPoint Gateway on Azure (see About Gateways)
  • A token is assigned to a user in AuthPoint

Mobile VPN with IKEv2 does not support OTP authentication. If you need to use OTP authentication, such as with a hardware token, we recommend that you configure AuthPoint MFA for Mobile VPN with SSL.

Additional charges might apply for the use of Microsoft Azure. To learn more about Microsoft Azure, go to What is Microsoft Entra Domain Services.

Configure AuthPoint MFA for Firebox Cloud Mobile VPN with IKEv2

The steps to configure AuthPoint and your Firebox Cloud are different based on the Fireware version of your Firebox Cloud. With Fireware v12.7.1 or higher, you can use the AuthPoint authentication server on your Firebox Cloud to make configuration easier, and you do not need to deploy the AuthPoint Gateway in Azure.