Two-Factor Authentication (2FA) for Device Access

Access to management protocols (e.g., WEBconfig, SSH, Telnet) can be secured using two-factor authentication (2FA) in addition to the regular password. The feature can be configured separately for additional administrators or for the default root user.

In certain cases, management protocols must be allowed over unsecure channels, such as the Internet. To provide additional protection and safeguard the device against brute-force attacks, two-factor authentication can be enabled granularly for different access paths.

Common authenticator apps for mobile devices, such as smartphones, are supported.

Note that in the event of loss of the authenticator, a complete device reset may be required in the worst case. It is therefore recommended not to require 2FA for all configuration access methods — for example, not for serial console access or local LAN access — so that in the event of loss or misconfiguration, the device can still be accessed through normal means without 2FA.

It is especially recommended to enable 2FA protection for access via the WAN interface, including the use of encrypted protocols such as HTTPS or SSH.

Using 2FA requires the device to have the correct time. Therefore, the time reference should always be configured via the NTP client on the router in LANconfig under Date & Time > Synchronization.

The basic configuration process for two-factor authentication is as follows:
  1. Create an entry in the "Admin-OTPs" table (LANconfig: Management > Admin > Device configuration > Admin OTPs), specifying the administrator account name to which this entry applies.
  2. Open WEBconfig under Extras > Admin-OTPs. From there, the generated QR code for the user can be displayed, saved, or scanned by an external authenticator app.
  3. When the management connection for the admin user is initiated, the user will be prompted to enter the one-time password (OTP) after entering their regular password.

Generating QR Codes for Connection with the Authenticator

The QR codes used to connect the authenticator with the device are generated in WEBconfig under Extras > Admin-OTPs or alternatively via the CLI command "show Admin-OTP-QR".

Show Commands

www.lancom-systems.com

LANCOM Systems GmbH | A Rohde & Schwarz Company | Adenauerstr. 20/B2 | 52146 Wuerselen | Germany | E‑Mail info@lancom.de

LANCOM Logo