This document provides information on how to access Terminal Proxy using Duo Push authentication.
Requirements
- Access to Terminal Proxy.
- A compatible SSH client.
- Duo configured as the multifactor authentication method on the Segura® Platform. More information in How to register a Duo Security MFA authentication provider.
- Duo Mobile application configured on the mobile device.
Attention
Only the standard Duo Mobile Push authentication method is currently supported by the platform for Terminal Proxy. Do not enable the Verified Duo Push option.
Step 1: Enable MFA to start a session
- On the Segura® Platform, hover over the Products menu and select Settings.
- In the side menu, select System parameters > Global.
- Open the Security tab and enable the Force multi-factor authentication to start a session? * parameter.
Step 2: Start the connection
- Open the SSH client.
- Start the SSH connection to the Segura® Platform using the user with Duo MFA enabled.
- Enter the authentication credentials.
- On the mobile device, locate the notification sent by the Duo Mobile application.
- Approve the authentication request.
Step 3: Access the target device
- After accessing the Segura® Platform environment, connect to the target device.
- On the mobile device, locate the notification sent by the Duo Mobile application.
- Approve the authentication request.
- Confirm that the session started successfully.
Optional: Access the target device directly with multi-hop
- Open the SSH client.
- Connect to the Segura® Platform via SSH.
- Enter your password or authentication token.
- On the mobile device, locate the first notification sent by the Duo Mobile application, referring to the vault access.
- Approve the first authentication request.
- On the mobile device, locate the second notification sent by the Duo Mobile application, referring to the target device access.
- Approve the second authentication request.
- Confirm that the session started successfully.
Attention
If either of the 2 authentication requests is denied in Duo Mobile, the proxy will terminate the access attempt.
After completing the steps above, the Terminal Proxy session will be established following Duo Push authentication approval on the mobile device.