Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure local user for OTP-based authentication

Want to summarize with AI?

Log in

Configure OTP-based two-factor authentication for a local user using the Cisco APIC GUI to enhance security by requiring both password and time-based token authentication.


This task enables OTP-based two-factor authentication for local users to enhance security by requiring both password and time-based token authentication for user access.

The following procedure configures OTP-based two-factor authentication for a local user using the Cisco APIC GUI. The procedure assumes that you are a fabric administrator.

Before you begin

You must have already created a local user for which you want to enable OTP-based two-factor authentication.

Follow these steps to configure OTP-based two-factor authentication for a local user:

Procedure

  1. On the menu bar, choose Admin > AAA.

  2. In the Navigation pane, choose Users.

  3. In the Work pane, click the user for which you want to enable OTP-based two-factor authentication.

    A window is displayed on the right which has more details about the user. Click the Details (The user details window shows options for configuring OTP-based authentication, including fields for entering the user's phone number and selecting authentication methods.) icon, and in the new screen that is displayed (with user details), click the Edit icon.

  4. Scroll down, and under Advanced Settings, select the Enable check-box for OTP.

  5. Click Save.

    To get the OTP details, on the Users > Local tab, click the User_name > Details icon, to get the user details screen. Click the displayed OTP Key to see the QR code. The user details screen is as shown below.

    The user details screen displays the OTP key and QR code for enabling OTP-based two-factor authentication for the selected local user.

OTP-based two-factor authentication is now enabled for the selected local user. The user can now view the OTP key and QR code to complete their authentication setup.

What to do next

The user for which you enabled OTP must complete the configuration of OTP authentication. See Complete the configuration of OTP-based two-factor authentication by a user using the GUI .


Complete the configuration of OTP-based two-factor authentication by a user using the GUI

This task completes the setup of OTP-based two-factor authentication for your user account after a fabric administrator has enabled it.

The following procedure completes the configuration of OTP-based two-factor authentication using the Cisco APIC GUI. The procedure assumes that you are a user for which a fabric administrator enabled OTP-based two-factor authentication.

Before you begin

A fabric administrator must have enabled OTP-based two-factor authentication for your account.

Procedure

  1. On your Android or Apple iOS smartphone, download the appropriate two-factor authentication app.

  2. Get the QR code or OTP key from the fabric administrator or by logging in to the Cisco APIC GUI.

    If you log into the GUI, the QR code and OTP key display after you enter your credentials.

  3. Using your smartphone, scan the QR code and follow the two-factor authentication app's directions, or enter the OTP key in the Cisco APIC GUI.

OTP-based two-factor authentication is now configured and active for your user account.