18
Votes

2FA for VPN

 
18
Votes

2FA for VPN

58 Reply
Re:2FA for VPN
2026-01-20 14:47:38

seki1975 wrote

  @DaveMcDave 

It's a great shame that such a large company as TP-LINK hasn't been able to solve this yet, perhaps through QR or some other method... the question is whether they will solve it at all... and yet they sell their most expensive network products as "BUSINESS class", which has nothing to do with this segment, I would say, because 2FA authentication is the very basis of VPN security.

  @seki1975 

 

I agree that 2fa would have been nice to have on the Omada controller, but I am very interested in what you write, you make it sound like all enterprise solutions have 2fa built in as standard, do you have any examples of who comes with this in their solutions without being dependent on third party software? You can use 2fa with Omada if you use, for example, Microsoft Radius Server and Omada SSL Server. I have worked a lot with Cisco Unifi and Mikrotik in recent years, none of them have 2fa built in. So again I am very interested in products with 2fa as standard out of the box.

 

 

#54
Re:2FA for VPN
2026-01-20 15:44:35 - last edited 2026-01-20 15:48:13

  @MR.S 

Vigor3910, Vigor2962, firmware version 4.3.2 or later .....about 5 years old device....

#55
Re:2FA for VPN
2026-01-20 16:27:56

  @seki1975 

 

A router that has 2FA out of the box, yes that's not bad, I guess Omada comes with 2FA too so then there will be two that have 2FA. We'll give them some time in the meantime, Vigor routers are a good alternative for anyone who wants 2FA out of the box.

 

#56
Re:2FA for VPN
2026-01-20 16:30:46 - last edited 2026-01-20 16:32:04

  @MR.S 

I wrote this here before in the forum...but it's been about a year and no change, so TP LINK has also improved it? It seems not....I have OMADA but I use it locally in the installation room not in front of CLOUD OMADA .....ER706W v1.0

#57
Re:2FA for VPN
Yesterday - last edited Yesterday

Good day one and all!

 

So it's been a fair while now and still nothing. We've found ways around this to a degree, but it would be just soooooo much easier if it was a tick box for "Allow 2FA" and then you give the user a QR code.

 

I take it at this point that itt's just a no go and we should give up on hopes of this ever becoming a feature? I'm actually amazed that this hasn't been requested more!

#58
Re:2FA for VPN
10 hours ago

  @DaveMcDave 

and how did you solve 2FA in TP-Link?

#59
Re:2FA for VPN
6 hours ago - last edited 6 hours ago

  @seki1975 

 

We basically setup an external RADIUS server in the SSLVPN that points to a PrivacyIdea server. The way it works is that it uses a standard password + the TOTP at the end, so if your password is PASSWORD and yout TOTP code is 123456, then your password for your VPN connection is PASSWORD123456. Reason why it was setup like this is something to do with the OpenVPN in the Omada not accepting challenge requests (or something like that! One of our nerdy guys set this up!).

 

Whilst not true 2FA, it's certainly better than what TP Link has given us! Just imagine what a great product the whole Omada system could be if they would just add native 2FA VPN into it! 

#60
Re:2FA for VPN
6 hours ago - last edited 6 hours ago

  @DaveMcDave 

 

I understand, I use wireguard and I was also considering 2FA there but I don't know how to do it in this case

#61