I have an insurance company, providing cyber insurance, with a stated requirement for the following:
MFA authentication for all internal and remote admin access to network infrastructure: firewalls, routers, switches, etc.
I presume that having 2FA on workstation Windows logons (which *we* would use to access those network devices) doesn't satisfy this. How does one provide 2FA for things like Cisco Small Business Switches?
How would you deal with this question/requirement?
We had one of our auditors do that. But maybe I don't understand....
The requirement was settled by setting up DUO 2FA on their Remote Desktop Gateway and Web site along with the Windows authentication component on the servers so that 2FA is needed to log on to the desktop/console.
Essentially, no one could get in to the network without a DUO prompt.
SSL VPN was disabled to also comply with the requirement.