Documentation
Duo Two-Factor Authentication with LDAPS for Juniper Secure Access SSL VPN (Deprecated)
Last Updated: November 21st, 2024Contents
The end-of-life date for Juniper SA SSL VPN is February 20, 2025. Users logging into these applications will no longer be able to authenticate as of this date.
Direct LDAP connectivity to Duo for Juniper SA SSL VPN reached the end of support on March 30, 2024. Customers may not create new Juniper SSL VPN applications after September 2023.
We recommend you deploy Duo Single Sign-On for Ivanti Connect Secure to protect Juniper SA SSL VPN with Duo Single Sign-On, our cloud-hosted identity provider featuring Duo Central and the Duo Universal Prompt.
Another alternative to direct LDAPS connections is adding Duo authentication to Juniper SA SSL VPN using RADIUS and the Duo Authentication Proxy, for example, RADIUS with Automatic Push for Juniper SA SSL VPN. See the "Related" links to the left to explore more RADIUS configurations.
Please visit the article Guide to end of support for the Duo LDAP cloud service (LDAPS) used to provide 2FA for Cisco ASA, Juniper Networks Secure Access, and Pulse Secure Connect Secure SSL VPN for further details, and review the Duo End of Sale, Last Date of Support, and End of Life Policy.
The instructions for this solution were removed on November 21, 2024. Customers who had this configuration deployed before then and need to refer to the original instructions may contact Duo Support.
Troubleshooting
Need some help? Take a look at the Juniper Frequently Asked Questions (FAQ) page or try searching our Juniper Knowledge Base articles or Community discussions. For further assistance, contact Support.
Network Diagram
- SSL VPN connection initiated
- Primary authentication
- Juniper MAG/SA connection established to Duo Security over TCP port 636
- User completes Duo two-factor authentication via the interactive web prompt served from Duo's service or text response to the MAG/SA and their selected authentication factor.
- Juniper MAG/SA receives authentication response
- SSL VPN connection established