Integration Guides

GreenRADIUS can integrate with a wide variety of applications, network devices, operating systems, and identity platforms to enforce two-factor authentication. The appropriate integration method depends on the authentication interfaces supported by the system being protected.

For VPNs, firewalls, and other network devices that support RADIUS authentication, GreenRADIUS can generally be configured as a standard RADIUS authentication server. GreenRADIUS currently supports PAP, PEAP, and EAP-TTLS-GTC for RADIUS authentication. CHAP, MS-CHAP, and MS-CHAPv2 are not supported.

GreenRADIUS also provides dedicated integration methods for Windows Logon, Linux PAM, ADFS, websites and applications, and FIDO2 authentication.

Choosing an Integration Method

What you want to protectGreenRADIUS integrationGuide
VPNs, firewalls, and other RADIUS-compatible network devicesRADIUSAuthentication Requests
FortiGate VPNRADIUSFortiGate VPN Integration
NetMotionRADIUSNetMotion Integration
Cisco ASARADIUSCisco ASA Integration
Palo Alto Networks VPNRADIUSPalo Alto VPN Integration
Pulse SecureRADIUSPulse Secure Integration
WatchGuardRADIUSWatchGuard Integration
Check Point VPNRADIUSCheck Point VPN Integration
OpenVPNRADIUSOpenVPN Integration
pfSenseRADIUSpfSense Integration
Windows desktop, Windows Server, or RDP loginsGreenRADIUS Windows Logon AgentWindows Logon
Linux SSH, console, sudo, or GNOME loginsGRS PAM HTTPS ModuleGRS PAM HTTPS Module
Ubuntu SSH using PAM and RADIUSPAM RADIUSGreenRADIUS PAM RADIUS Module for Ubuntu
RedHat SSH using PAM and RADIUSPAM RADIUSGreenRADIUS PAM RADIUS Module for RedHat
Microsoft ADFSGreenRADIUS ADFS MFA AdapterGreenRADIUS 2FA for ADFS
WordPressGreenRADIUS WordPress Plugin2FA for WordPress with GreenRADIUS
Custom websites and applicationsGreenRADIUS Web APIGreenRADIUS Web API Guide
FIDO2 for supported RADIUS, LDAP, and API integrationsGRS FIDO2 Authenticator AppGRS FIDO2 Authenticator App

Before You Begin

Before configuring an integration:

  1. Make sure GreenRADIUS has been deployed and is reachable from the system being integrated.
  2. Configure the appropriate user directory and import the users who will use two-factor authentication.
  3. Review the prerequisites in the applicable integration guide. Some integrations require a specific GreenRADIUS license module or client component.
  4. For RADIUS integrations, add the application, server, firewall, or other device as a RADIUS client under Global Configuration > Client-based Authentication Policies, and configure the same shared secret on both systems.
  5. Test authentication before deploying the integration to production users.

If your application or device supports standard RADIUS but does not have a dedicated integration guide listed above, GreenRADIUS can generally be integrated by configuring GreenRADIUS as the RADIUS authentication server. See Authentication Requests for supported RADIUS authentication methods and general configuration information.

Updated 2026-08-21
© 2026 Green Rocket Security Inc. All rights reserved.