Integrations · VPN & remote access

MFA for every VPN.

Your VPN gateway already speaks RADIUS. Point it at Mideye and every VPN logon gets a second factor: a push on the user's phone, an SMS code, or a hardware token. No agents, no directory changes, no rip-and-replace.

  • Standard RADIUS
  • Users stay in AD
  • Air-gapped option

Step-by-step guides

Your gateway, documented.

Each guide walks through the gateway-side RADIUS configuration and the matching Mideye Server settings, tested against the vendor's current releases.

Palo Alto Networks

  • GlobalProtect gateway and portal
  • RADIUS authentication profile setup
GlobalProtect guide

Fortinet

  • FortiGate SSL VPN and IPsec
  • RADIUS server object configuration
FortiGate guide

Running F5 BIG-IP APM, SonicWALL, or another gateway not listed here? The RADIUS configuration is the same standard pattern. Talk to an engineer and we will walk it through with you.

Isolated networks

VPN MFA without internet egress.

Air-gapped mode for OT and defence networks.

In air-gapped mode, the Mideye Server validates hardware-token OTPs entirely on-premises. No cloud dependency, no outbound connection, same RADIUS integration on the gateway side.

FAQ

Frequently asked questions.

How do I add MFA to my VPN?

Point your VPN gateway's RADIUS authentication at the Mideye Server. Users log in with their usual directory credentials; Mideye adds the second factor as a Mideye+ push, an SMS one-time code, or a hardware-token OTP. No agents on the gateway, no changes to your user directory.

Which VPN vendors does Mideye support?

Any VPN that speaks RADIUS. We publish step-by-step guides for Cisco AnyConnect (ASA and FMC), Palo Alto GlobalProtect, Fortinet FortiGate, Check Point, Pulse Connect Secure / Ivanti, and Microsoft VPN (RRAS). Other RADIUS-capable gateways, such as F5 BIG-IP APM and SonicWALL, use the same standard configuration.

Does VPN MFA work without internet access?

Yes. In air-gapped mode the Mideye Server validates hardware-token OTPs entirely on-premises, with no internet egress. This suits isolated OT and defence networks where a cloud dependency is not acceptable.

Protect your VPN this week.

Most RADIUS integrations complete in hours. We plan a proof-of-concept with your IT team, with an evaluation license and support from our engineers.