이 문서에서는 Firepower Management Center에서 관리 액세스를 위한 외부 2단계 인증을 구성하는 데 필요한 단계에 대해 설명합니다.
다음 주제에 대한 지식을 보유하고 있으면 유용합니다.
이 문서의 정보는 특정 랩 환경의 디바이스를 토대로 작성되었습니다. 이 문서에 사용된 모든 디바이스는 초기화된(기본) 컨피그레이션으로 시작되었습니다. 현재 네트워크가 작동 중인 경우 모든 명령의 잠재적인 영향을 미리 숙지하시기 바랍니다.
FMC 관리자가 ISE 서버에 대해 인증하고 Duo Authentication Proxy 서버에서 푸시 알림 형태의 추가 인증을 관리자의 모바일 디바이스로 전송합니다.

컨피그레이션을 완료하려면 다음 섹션을 고려하십시오.
1단계. System(시스템) > Users(사용자) > External Authentication(외부 인증)으로 이동합니다. 외부 인증 객체를 생성하고 인증 방법을 RADIUS로 설정합니다. 기본 사용자 역할에서 관리자가 선택되었는지 확인합니다.


Save and Apply(저장 및 적용)를 클릭합니다(경고 무시).

2단계. System(시스템) > Users(사용자) > Users(사용자)로 이동합니다. 사용자를 생성하고 Authentication Method(인증 방법)를 External(외부)로 선택합니다.

3단계. Duo 인증 프록시 서버를 다운로드하고 설치합니다.
Windows 시스템에 로그인하고 Duo 인증 프록시 서버 설치
Cisco에서는 최소 1개의 CPU, 200MB의 디스크 공간 및 4GB RAM이 있는 시스템을 사용하는 것이 좋습니다.
4단계. authproxy.cfg 파일을 구성합니다.
Notepad++ 또는 WordPad와 같은 텍스트 편집기에서 이 파일을 엽니다.
authproxy.cfg 파일을 편집하고 이 구성을 추가합니다.
[radius_client]
host=10.197.223.23 Sample IP Address of the ISE server
secret=cisco Password configured on the ISE server in order to register the network device
FMC의 IP 주소는 RADIUS 비밀 키와 함께 구성되어야 합니다.
[radius_server_auto]
ikey=xxxxxxxxxxxxxxx
skey=xxxxxxxxxxxxxxxxxxxxxxxxxxx
api_host=api-xxxxxxxx.duosecurity.com
radius_ip_1=10.197.223.76 IP of FMC
radius_secret_1=cisco Radius secret key used on the FMC
failmode=safe
client=radius_client
port=1812
api_timeout=
ikey, skey 및 api_host 매개변수를 구성해야 합니다. 이러한 값을 얻으려면 Duo 계정에 로그인하고(Duo Admin Login) Applications > Protect an Application으로 이동합니다. 다음으로 RADIUS 인증 애플리케이션을 선택합니다.

5단계. Duo Security Authentication Proxy 서비스를 다시 시작합니다. 파일을 저장하고 Windows 시스템에서 Duo 서비스를 다시 시작합니다.
Windows 서비스 콘솔(services.msc)을 엽니다. 서비스 목록에서 Duo Security Authentication Proxy Service(Duo 보안 인증 프록시 서비스)를 찾고 Restart(재시작)를 클릭합니다.

1단계. Administration(관리) > Network Devices(네트워크 디바이스)로 이동합니다. Add(추가)를 클릭하여 네트워크 디바이스를 구성합니다.

* 공유 암호의 authproxy.cfg에 설명된 대로 공유 암호를 구성합니다.

2단계. Administration(관리) >Identities(ID)로 이동합니다. Add(추가)를 클릭하여 ID 사용자를 구성합니다.

1단계. 사용자 이름을 생성하고 디바이스에서 Duo Mobile을 활성화합니다.
Duo Cloud 관리 웹 페이지에서 사용자를 추가합니다. 사용자 > 사용자 추가로 이동합니다.

2단계. 코드 자동 생성
사용자 전화 번호를 추가합니다.


Activate Duo Mobile을 선택합니다.

이미지에 표시된 대로 Generate Duo Mobile Activation Code(Duo Mobile 활성화 코드 생성)를 선택합니다.

이미지에 표시된 대로 Send Instructions by SMS(SMS로 지침 보내기)를 선택합니다.

SMS에서 링크를 클릭하면 Duo 앱이 Device Info(디바이스 정보) 섹션의 사용자 계정에 연결됩니다.

이 섹션을 사용하여 컨피그레이션이 제대로 작동하는지 확인합니다.
1단계. ISE 사용자 ID 페이지에 추가된 사용자 자격 증명을 사용하여 FMC에 로그인합니다. Two Factor Authentication(2FA)의 엔드포인트에 대해 Duo 푸시 알림을 수신해야 합니다. 승인해야 하며 FMC에서 로그인합니다.

2단계. ISE 서버에서 Operations(운영) > RADIUS > Live Logs(라이브 로그)로 이동합니다. FMC에서 인증에 사용되는 사용자 이름을 찾은 다음 세부 정보 열에서 세부 정보 인증 보고서를 선택합니다. 인증이 성공했는지 확인해야 합니다.

이 섹션에서는 컨피그레이션 트러블슈팅을 위한 추가 정보를 제공합니다.
잘못된 자격 증명이 입력되고 ISE 서버에서 인증이 거부될 경우 스니펫을 기록합니다.
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Sending request from 10.197.223.76 to radius_server_auto 10.197.223.76 is the IP of the FMC
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Received new request id 4 from ('10.197.223.76', 34524)
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] (('10.197.223.76', 34524), 4): login attempt for username u'cpiplani'
2019-08-04T18:54:17+0530 [DuoForwardServer (UDP)] Sending request for user u'cpiplani' to ('10.197.223.23', 1812) with id 199
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] Got response for id 199 from ('10.197.223.23', 1812); code 3 10.197.223.23 is the IP of the ISE Server.
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Primary credentials rejected - No reply message in packet
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Returning response code 3: AccessReject
2019-08-04T18:54:17+0530 [RadiusClient (UDP)] (('10.197.223.76', 34524), 4): Sending response
ISE 서버에서 Operations(운영) >RADIUS> Live Logs(라이브 로그)로 이동하여 인증 세부사항을 확인합니다.
ISE 및 Duo를 사용한 성공적인 인증의 조각 기록:
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Sending request from 10.197.223.76 to radius_server_auto
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Received new request id 5 from ('10.197.223.76', 34095)
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] (('10.197.223.76', 34095), 5): login attempt for username u'cpiplani'
2019-08-04T18:56:16+0530 [DuoForwardServer (UDP)] Sending request for user u'cpiplani' to ('10.197.223.23', 1812) with id 137
2019-08-04T18:56:16+0530 [RadiusClient (UDP)] Got response for id 137 from ('10.197.223.23', 1812); code 2 <<<< At this point we have got successful authentication from ISE Server.
2019-08-04T18:56:16+0530 [RadiusClient (UDP)] http POST to https://api-f754c261.duosecurity.com:443/rest/v1/preauth
2019-08-04T18:56:16+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/preauth>
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Got preauth result for: u'auth'
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] Invalid ip. Ip was None
2019-08-04T18:56:17+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] http POST to https://api-f754c261.duosecurity.com:443/rest/v1/auth
2019-08-04T18:56:17+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/auth>
2019-08-04T18:56:17+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/preauth>
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Duo authentication returned 'allow': 'Success. Logging you in...'
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Returning response code 2: AccessAccept <<<< At this point, user has hit the approve button and the authentication is successful.
2019-08-04T18:56:30+0530 [HTTPPageGetter (TLSMemoryBIOProtocol),client] (('10.197.223.76', 34095), 5): Sending response
2019-08-04T18:56:30+0530 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory <_DuoHTTPClientFactory: https://api-f754c261.duosecurity.com:443/rest/v1/auth>
| 개정 | 게시 날짜 | 의견 |
|---|---|---|
3.0 |
02-Jun-2026
|
업데이트된 맞춤법, 문법, 간격 등 |
2.0 |
15-Jun-2023
|
PII를 제거했습니다.
대체 텍스트를 추가했습니다.
업데이트된 제목, 소개, SEO, 기계 번역, 스타일 요구 사항 및 서식. |
1.0 |
20-Aug-2019
|
최초 릴리스 |