SecurID® Integrations

Cisco FTD - RSA SecurID Access Implementation Guide

Cisco Systems, Inc.

Firepower Threat Defense (FTD) 6.3


Pete Waranowski, RSA Partner Engineering

Last Modified: January 25th, 2019


Solution Summary

This section shows all of the ways that Cisco FTD can integrate with RSA SecurID Access. Use this information to determine which use case and integration type your deployment will employ.

Use Case

Remote Access VPN (AnyConnect) - When integrated, users must authenticate with RSA SecurID Access in order to establish a VPN connection to Cisco FTD using Cisco AnyConnect VPN client. Remote Access VPN can be integrated with RSA SecurID Access using RADIUS.


Integration Type

RADIUS integrations provide a text driven interface for RSA SecurID Access within the partner application. RADIUS provides support for most RSA SecurID Access authentication methods and flows.

Supported Features

This section shows all of the supported features by integration type and by RSA SecurID Access component. Use this information to determine which integration type and which RSA SecurID Access component your deployment will use. The next section in this guide contains the instruction steps for how to integrate RSA SecurID Access with CiscoFTD using each integration type.


Cisco FTD integration with RSA Cloud Authentication Service

Authentication Methods

Authentication API


Relying Party

SSO Agent

RSA SecurID---
LDAP Password---
Authenticate Approve---
Authenticate Tokencode---
Device Biometrics---
SMS Tokencode---
Voice Tokencode---
FIDO Tokenn/an/a--


Cisco FTD integration with RSA Authentication Manager

Authentication Methods

Authentiaction API

RADIUSAuthentication Agent
RSA SecurID--
On Demand Authentication--
Risk-Based Authenticationn/a--


- Not supported
n/tNot yet tested or documented, but may be possible.

Configuration Summary

This section contains links to the sections that contain instruction steps that show how to integrate Cisco FTD with RSA SecurID Access using all of the integration types and also how to apply them to each supported use case. First configure the integration type (e.g. RADIUS) then configure the use case (e.g. Remote Access VPN).

This document is not intended to suggest optimum installations or configurations. It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products in order to install the required components. All RSA SecurID Access and Cisco FTD components must be installed and working prior to the integration.

Integration Configuration



Use Case Configuration

Remote Access VPN


Certification Details

Date of testing: January 24th, 2019

RSA Cloud Authentication Service

RSA Authentication Manager 8.3, Virtual Appliance

Cisco FTD 6.3, Virtual Appliance


Known Issues


Labels (1)
No ratings
Version history
Last update:
‎2019-01-25 02:51 PM
Updated by:
Article Dashboard