Integration Guides
GreenRADIUS can integrate with a wide variety of applications, network devices, operating systems, and identity platforms to enforce two-factor authentication. The appropriate integration method depends on the authentication interfaces supported by the system being protected.
For VPNs, firewalls, and other network devices that support RADIUS authentication, GreenRADIUS can generally be configured as a standard RADIUS authentication server. GreenRADIUS currently supports PAP, PEAP, and EAP-TTLS-GTC for RADIUS authentication. CHAP, MS-CHAP, and MS-CHAPv2 are not supported.
GreenRADIUS also provides dedicated integration methods for Windows Logon, Linux PAM, ADFS, websites and applications, and FIDO2 authentication.
Choosing an Integration Method
| What you want to protect | GreenRADIUS integration | Guide |
|---|---|---|
| VPNs, firewalls, and other RADIUS-compatible network devices | RADIUS | Authentication Requests |
| FortiGate VPN | RADIUS | FortiGate VPN Integration |
| NetMotion | RADIUS | NetMotion Integration |
| Cisco ASA | RADIUS | Cisco ASA Integration |
| Palo Alto Networks VPN | RADIUS | Palo Alto VPN Integration |
| Pulse Secure | RADIUS | Pulse Secure Integration |
| WatchGuard | RADIUS | WatchGuard Integration |
| Check Point VPN | RADIUS | Check Point VPN Integration |
| OpenVPN | RADIUS | OpenVPN Integration |
| pfSense | RADIUS | pfSense Integration |
| Windows desktop, Windows Server, or RDP logins | GreenRADIUS Windows Logon Agent | Windows Logon |
| Linux SSH, console, sudo, or GNOME logins | GRS PAM HTTPS Module | GRS PAM HTTPS Module |
| Ubuntu SSH using PAM and RADIUS | PAM RADIUS | GreenRADIUS PAM RADIUS Module for Ubuntu |
| RedHat SSH using PAM and RADIUS | PAM RADIUS | GreenRADIUS PAM RADIUS Module for RedHat |
| Microsoft ADFS | GreenRADIUS ADFS MFA Adapter | GreenRADIUS 2FA for ADFS |
| WordPress | GreenRADIUS WordPress Plugin | 2FA for WordPress with GreenRADIUS |
| Custom websites and applications | GreenRADIUS Web API | GreenRADIUS Web API Guide |
| FIDO2 for supported RADIUS, LDAP, and API integrations | GRS FIDO2 Authenticator App | GRS FIDO2 Authenticator App |
Before You Begin
Before configuring an integration:
- Make sure GreenRADIUS has been deployed and is reachable from the system being integrated.
- Configure the appropriate user directory and import the users who will use two-factor authentication.
- Review the prerequisites in the applicable integration guide. Some integrations require a specific GreenRADIUS license module or client component.
- For RADIUS integrations, add the application, server, firewall, or other device as a RADIUS client under Global Configuration > Client-based Authentication Policies, and configure the same shared secret on both systems.
- Test authentication before deploying the integration to production users.
If your application or device supports standard RADIUS but does not have a dedicated integration guide listed above, GreenRADIUS can generally be integrated by configuring GreenRADIUS as the RADIUS authentication server. See Authentication Requests for supported RADIUS authentication methods and general configuration information.
© 2026 Green Rocket Security Inc. All rights reserved.