KeycloakPro

Workforce MFA · VPN MFA (RADIUS)

MFA for every VPN, backed by one Keycloak policy

Most VPNs can check a second factor over RADIUS, and many can hand sign-in to a SAML identity provider. We connect yours to Keycloak the best way it supports — so remote access uses the same users, groups and MFA as everything else.

  • RADIUS and SAML options
  • OTP, push and challenge prompts
  • Group-based VPN access

Standards & integrations

  • RADIUS
  • PAP
  • Access-Challenge
  • SAML 2.0
  • TOTP
  • LDAP / Active Directory

Overview

RADIUS or SAML: the right path for each VPN

RADIUS is the common denominator: almost every VPN can send it, and it can carry a password plus a one-time code or wait for a push approval. Keycloak has no RADIUS server built in, so we add a RADIUS front end — an open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak. Where the VPN supports SAML, users sign in on Keycloak's own login page instead, which unlocks passkeys and every other factor Keycloak supports.

What we deliver

  • VPN inventory with a RADIUS or SAML decision per gateway
  • Highly available RADIUS front end for Keycloak
  • Gateway configuration for each VPN vendor
  • MFA flow design for OTP, challenge and push
  • Group-to-VPN policy mapping
  • User enrolment guide and support runbook

Capabilities

What VPN MFA (RADIUS) covers

Configured, tested and documented on upstream Keycloak — then handed over or operated by us.

  • RADIUS front end for Keycloak

    An open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak, pinned to your Keycloak version and tested on every upgrade.

  • SAML sign-in where supported

    VPN clients that support SAML send users to Keycloak's login page, so passkeys, conditional MFA and branding all apply.

  • OTP, challenge and push

    Codes appended to the password or requested through a RADIUS challenge; push approvals through a custom authenticator, with VPN timeouts raised to match.

  • Groups become VPN policy

    Keycloak groups are returned as RADIUS attributes or SAML claims that your VPN maps to access policies and address pools.

  • High availability

    RADIUS nodes run active-active and are configured as primary and secondary servers on every gateway.

  • One event trail

    VPN authentications appear in Keycloak's events next to web and desktop sign-ins, ready for your SIEM.

Compatibility

VPN compatibility

How each VPN connects to Keycloak. Client and firmware versions matter — we verify every gateway in a pilot before rollout.

PlatformIntegrationNotes
Cisco Secure Client (AnyConnect) on ASA / FTDSAML 2.0 or RADIUSSAML gives a browser-based Keycloak login; with RADIUS, raise the AAA timeout for push.
Palo Alto GlobalProtectSAML 2.0 or RADIUSRADIUS supports challenge prompts for OTP; SAML behaviour depends on client version.
Fortinet FortiGate / FortiClientSAML 2.0 or RADIUSIncrease the remote authentication timeout on the FortiGate for push approvals.
Check Point Remote AccessSAML 2.0 or RADIUSSAML through an identity provider object on recent releases; RADIUS as an authentication server.
Ivanti Connect SecureSAML 2.0 or RADIUSSupports RADIUS challenge for OTP and SAML sign-in realms.
SonicWall SSL VPNRADIUS; SAML on newer firmwareConfirm SAML support for your SonicOS version and client.
Citrix NetScaler GatewaySAML 2.0 or RADIUSnFactor flows can combine an LDAP password with a RADIUS one-time code.
OpenVPN Access ServerSAML 2.0 or RADIUSSAML is available on recent Access Server releases; RADIUS uses PAP.
WatchGuard FireboxRADIUSMobile VPN users authenticate against a RADIUS server; set timeouts for push.
Sophos FirewallRADIUSRemote access VPN users authenticate against a RADIUS server.
pfSense / OPNsenseRADIUSOpenVPN and IPsec remote access authenticate against a RADIUS server.
Azure VPN Gateway (point-to-site)RADIUSIts built-in Entra ID option is tied to Entra; RADIUS works with Keycloak.
AWS Client VPNSAML 2.0 federationClient VPN supports SAML federation with a SAML 2.0 identity provider such as Keycloak.

How it works

From first call to production

  1. Inventory gateways and clients

    We list every VPN gateway, firmware and client version and choose RADIUS or SAML for each based on what it supports.

  2. Build and test per gateway

    The RADIUS front end and Keycloak flows are configured, then each gateway is tested with OTP, challenge and push in a pilot group.

  3. Enrol users and switch groups

    Users enrol their second factor in Keycloak, and VPN groups switch over in waves with the old method kept as a fallback until cut-over.

Use cases

Where teams put it to work

  • Replacing a separate MFA service

    Move VPN MFA onto the Keycloak you already run instead of maintaining a separate MFA product for remote access.

  • Mixed VPN estates after mergers

    Put Cisco, Fortinet and Palo Alto gateways from different business units behind one MFA policy.

  • Contractor remote access

    Time-limited VPN access tied to Keycloak groups and removed automatically when a contract ends.

FAQ

VPN MFA (RADIUS) questions, answered

Does Keycloak support RADIUS?

Not out of the box. We add a RADIUS front end — an open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak — and test it against your Keycloak version on every upgrade.

Should we use RADIUS or SAML?

SAML if your VPN client supports it well: users get Keycloak's full login page, including passkeys. RADIUS when it doesn't, or for older clients that can't open a browser-based sign-in.

Why do push approvals time out?

Many VPNs wait only a few seconds for a RADIUS reply by default. Push needs that timeout raised on the gateway or on any RADIUS proxy in between; we set and test it for each gateway.

Can users keep their Active Directory password?

Yes. Keycloak federates Active Directory, so the first factor stays the AD password and Keycloak adds the second factor.

Ready to roll out VPN MFA (RADIUS)?

Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.

Browse all solutions