Workforce MFA · VPN MFA (RADIUS)
MFA for every VPN, backed by one Keycloak policy
Most VPNs can check a second factor over RADIUS, and many can hand sign-in to a SAML identity provider. We connect yours to Keycloak the best way it supports — so remote access uses the same users, groups and MFA as everything else.
- RADIUS and SAML options
- OTP, push and challenge prompts
- Group-based VPN access
Standards & integrations
- RADIUS
- PAP
- Access-Challenge
- SAML 2.0
- TOTP
- LDAP / Active Directory
Overview
RADIUS or SAML: the right path for each VPN
RADIUS is the common denominator: almost every VPN can send it, and it can carry a password plus a one-time code or wait for a push approval. Keycloak has no RADIUS server built in, so we add a RADIUS front end — an open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak. Where the VPN supports SAML, users sign in on Keycloak's own login page instead, which unlocks passkeys and every other factor Keycloak supports.
What we deliver
- VPN inventory with a RADIUS or SAML decision per gateway
- Highly available RADIUS front end for Keycloak
- Gateway configuration for each VPN vendor
- MFA flow design for OTP, challenge and push
- Group-to-VPN policy mapping
- User enrolment guide and support runbook
Capabilities
What VPN MFA (RADIUS) covers
Configured, tested and documented on upstream Keycloak — then handed over or operated by us.
RADIUS front end for Keycloak
An open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak, pinned to your Keycloak version and tested on every upgrade.
SAML sign-in where supported
VPN clients that support SAML send users to Keycloak's login page, so passkeys, conditional MFA and branding all apply.
OTP, challenge and push
Codes appended to the password or requested through a RADIUS challenge; push approvals through a custom authenticator, with VPN timeouts raised to match.
Groups become VPN policy
Keycloak groups are returned as RADIUS attributes or SAML claims that your VPN maps to access policies and address pools.
High availability
RADIUS nodes run active-active and are configured as primary and secondary servers on every gateway.
One event trail
VPN authentications appear in Keycloak's events next to web and desktop sign-ins, ready for your SIEM.
Compatibility
VPN compatibility
How each VPN connects to Keycloak. Client and firmware versions matter — we verify every gateway in a pilot before rollout.
| Platform | Integration | Notes |
|---|---|---|
| Cisco Secure Client (AnyConnect) on ASA / FTD | SAML 2.0 or RADIUS | SAML gives a browser-based Keycloak login; with RADIUS, raise the AAA timeout for push. |
| Palo Alto GlobalProtect | SAML 2.0 or RADIUS | RADIUS supports challenge prompts for OTP; SAML behaviour depends on client version. |
| Fortinet FortiGate / FortiClient | SAML 2.0 or RADIUS | Increase the remote authentication timeout on the FortiGate for push approvals. |
| Check Point Remote Access | SAML 2.0 or RADIUS | SAML through an identity provider object on recent releases; RADIUS as an authentication server. |
| Ivanti Connect Secure | SAML 2.0 or RADIUS | Supports RADIUS challenge for OTP and SAML sign-in realms. |
| SonicWall SSL VPN | RADIUS; SAML on newer firmware | Confirm SAML support for your SonicOS version and client. |
| Citrix NetScaler Gateway | SAML 2.0 or RADIUS | nFactor flows can combine an LDAP password with a RADIUS one-time code. |
| OpenVPN Access Server | SAML 2.0 or RADIUS | SAML is available on recent Access Server releases; RADIUS uses PAP. |
| WatchGuard Firebox | RADIUS | Mobile VPN users authenticate against a RADIUS server; set timeouts for push. |
| Sophos Firewall | RADIUS | Remote access VPN users authenticate against a RADIUS server. |
| pfSense / OPNsense | RADIUS | OpenVPN and IPsec remote access authenticate against a RADIUS server. |
| Azure VPN Gateway (point-to-site) | RADIUS | Its built-in Entra ID option is tied to Entra; RADIUS works with Keycloak. |
| AWS Client VPN | SAML 2.0 federation | Client VPN supports SAML federation with a SAML 2.0 identity provider such as Keycloak. |
How it works
From first call to production
Inventory gateways and clients
We list every VPN gateway, firmware and client version and choose RADIUS or SAML for each based on what it supports.
Build and test per gateway
The RADIUS front end and Keycloak flows are configured, then each gateway is tested with OTP, challenge and push in a pilot group.
Enrol users and switch groups
Users enrol their second factor in Keycloak, and VPN groups switch over in waves with the old method kept as a fallback until cut-over.
Use cases
Where teams put it to work
Replacing a separate MFA service
Move VPN MFA onto the Keycloak you already run instead of maintaining a separate MFA product for remote access.
Mixed VPN estates after mergers
Put Cisco, Fortinet and Palo Alto gateways from different business units behind one MFA policy.
Contractor remote access
Time-limited VPN access tied to Keycloak groups and removed automatically when a contract ends.
FAQ
VPN MFA (RADIUS) questions, answered
Does Keycloak support RADIUS?
Not out of the box. We add a RADIUS front end — an open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak — and test it against your Keycloak version on every upgrade.
Should we use RADIUS or SAML?
SAML if your VPN client supports it well: users get Keycloak's full login page, including passkeys. RADIUS when it doesn't, or for older clients that can't open a browser-based sign-in.
Why do push approvals time out?
Many VPNs wait only a few seconds for a RADIUS reply by default. Push needs that timeout raised on the gateway or on any RADIUS proxy in between; we set and test it for each gateway.
Can users keep their Active Directory password?
Yes. Keycloak federates Active Directory, so the first factor stays the AD password and Keycloak adds the second factor.
Ready to roll out VPN MFA (RADIUS)?
Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.