Aviatrix VPN User Authentication with an Okta API Token
There are two methods to authenticate a VPN user against Okta: using an Okta API Token or using the Aviatrix VPN SAML Client. This document shows you how to set up authentication using the Okta API Token.
There are two methods to authenticate a VPN user against Okta: using an Okta API
Token or using the
Aviatrix VPN SAML Client.
This document shows you how to set up authentication using the Okta API Token.Okta API Token is a method where the Aviatrix VPN Gateway authenticates against
Okta on behalf of VPN clients using the standard Okta API. When this method is
used, you can continue to use a native OpenVPN® client such as Tunnelblick while
using MFA authentication.Follow these steps to configure Okta authentication and MFA on a User VPN
Gateway in your environment:
Okta authentication can be enabled either at the Aviatrix Gateway launch time
or after the Aviatrix Gateway is launched. We highly recommend you configure
Okta after the gateway is launched.
If provided, the VPN username will be the account ID without the domain name. For example, if your Okta account is “[email protected]” and “aviatrixtest.com” is your Username Suffix, the VPN username should be “demoaviatrix”. If no value is provided for this field, you must enter the full username including domain name (for example, “[email protected]”).
Use the .ovpn file emailed to your test account or download it from Aviatrix
VPN Users.
Add the configuration to your VPN client.
Connect and log in.
Since Aviatrix Okta authentication uses API authentication, it uses the
default sign on policy of Okta. If you have configured Multi-factor
Authentication in Okta, then during VPN login, the end user needs to append
his MFA token to the password during authentication.
Was this page helpful?
⌘I
Assistant
Responses are generated using AI and may contain mistakes.