Skip navigation
Documentation

Duo Two-Factor Authentication with LDAPS for Pulse Connect Secure Access SSL VPN (Deprecated)

Last Updated: February 24th, 2025

Direct LDAP connectivity to Duo for Pulse Connect Secure SSL VPN reached the end of support on March 30, 2024 and reached end-of-life status on February 20, 2025. Customers may not create new Juniper SSL VPN (used with Pulse VPN) applications and users of existing LDAPS configurations may no longer authenticate.

The recommended migration path is to deploy Duo Single Sign-On for Ivanti Connect Secure to protect Pulse Connect Secure SSL VPN with Duo Single Sign-On, our cloud-hosted identity provider featuring Duo Central and the Duo Universal Prompt.

Another alternative to direct LDAPS connections is adding Duo authentication to Pulse Connect Secure SSL VPN using RADIUS and the Duo Authentication Proxy, for example, RADIUS with Automatic Push for Pulse Connect Secure SSL VPN. See the "Related" links to the left to explore more RADIUS configurations.

Please visit the article Guide to end of life for the Duo LDAP cloud service (LDAPS) used to provide 2FA for Cisco ASA, Juniper Networks Secure Access, and Pulse Secure Connect Secure SSL VPN for further details, and review the Duo End of Sale, Last Date of Support, and End of Life Policy.

The instructions for this solution were removed on November 21, 2024. Customers who had this configuration deployed before then and need to refer to the original instructions to execute the migration to a supported solution may contact Duo Support.

Troubleshooting

Need some help? Take a look at the Pulse Connect Secure Frequently Asked Questions (FAQ) page or try searching our Pulse Connect Secure Knowledge Base articles or Community discussions. For further assistance, contact Support.

Network Diagram

Duo and Pulse Connect Secure Authentication Network Diagram
  1. SSL VPN connection initiated
  2. Primary authentication
  3. Pulse Connect Secure connection established to Duo Security over TCP port 636
  4. User completes Duo two-factor authentication via the interactive web prompt served from Duo's service or text response to PCS and their selected authentication factor.
  5. Pulse Connect Secure receives authentication response
  6. SSL VPN connection established