Azure MFA Authentication Cloud Based with Cisco Remote Access VPN

Just wondering if we implement Microsoft Azure Multi-Factor Authentication (2MFA) via O365 Cloud based with Cisco Anyconnect VPN for remote authentication, is the Radius/NPS Integration done using the external interface or internal interface?

Usually with Cisco LDAPS authentication (through port 636 for Secure LDAP authentication) and Radius authentication, this is done through the internal interface so not too concern about the security and communication among the ASA and Radius server.

But if we go with Azure MFA Cloud based, just wondering how this will work and if it will be routed through the internet and how secure is it.  Is it through certificate or will a VPC needed as a prerequisite.

Thank you!
LateNaiteCEO and FounderAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Shreedhar EtteTechnical ManagerCommented:
The connection from Azure MFA to your infrastructure communication will be external.

Please refer below article for the requirment to implement MFA for Cisco ASA VPN:
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension-vpn
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension
LateNaiteCEO and FounderAuthor Commented:
Hi Shreedhar, this doesn't talk about how the NPS extension talks to the Cisco ASA VPN.  If we have Cloud based Azure, is the radius/NPS communication going over the outside interface to authenticate users?  When on-premise, this is all done internally on the inside interface, when it is fine but on the outside, there is a security concern there.
LateNaiteCEO and FounderAuthor Commented:
We're going a different route with this.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Office 365

From novice to tech pro — start learning today.