You are located in service: VPN (Virtual Private Network)

Setting up MFA for VPN (Authenticator App)

Setting up MFA for VPN (Authenticator App)

guide

 

Note

It is not possible to use the E-Mail token for the authentication in VPN.

On this page you will learn, how to set up a second factor for the multi-factor authentication using an authenticator app and use it to log in to the VPN:

Please watch our tutorial on setting up a token for VPN (opens in new tab).

Alternatively, you can use the following tokens for multi-factor authentication in the VPN:


Set up a valid token

To set up a valid token via the token manager in IdM Selfservice (opens in new tab), proceed as follows:

Step 1
Sign in into the IdM Selfservice.

Step 2
Choose Authenticator app e.g. for smartphone (TOTP) in the Token Manager in IdM Selfservice (opens in new tab).

Optional: Add a description (e.g. the name of your app) and select a security code length and hash algorithm under Advanced Options.

Step 3
Click on Create.

The TOTP token's configuration screen, which allows you to set a custom name and configure advanced options.

Step 4
Add a new service or a new account in your Authenticator App and scan the QR-Code with you device or enter the TOTP Key into the app.

Step 5
Enter a one-time-password (OTP) shown in the app in to the field Verify TOTP an click Finish to complete the procedure. 

The app token's QR code, with the token confirmation field below it. Below the input field are the Complete and Cancel buttons.

Example: Set up tokens in the 2FAS app

The steps in the app are the following (the cost free 2FAS App (opens in new tab) is used as an example) of a TOTP App:

Step 1
Open the app and click on pair new device.

Home screen of the 2FAS App.

 

Step 2
Scan the QR-code from the Token Manager with the app.

2FAS App: Pair the service with 2FAS

 

Step 3
Enter the one-time-password (OTP) from the app into the field in your browser and click Finish.

Confirmation Window for the Token setup.

You can now use the app as a Authenticator App e.g. for Smartphone (TOTP). A new one-time-password (OTP) is generated every 30 seconds.

Important:Ensure that no unauthorized third parties are able to access the app.

 

Connect to the VPN

To connect to an RWTH VPN, proceed as follows:

Step 1
Start AnyConnect and enter you vpn server (e.g. vpn.rwth-aachen.de). Establish the connection by selecting Connect.

VPN Server Input Window.

 

Step 2
Enter the following information:

  • Group: Choose the group RWTH-VPN (Full Tunnel) or RWTH-VPN (Split Tunnel)
  • Username: Your username in the format ab123456.
  • Password: Your VPN password.
    The VPN password can be changed in the IdM Selfservice.

Select OK to continue.

VPN Window for Entering Login Credentials.

 

Step 3
Enter a valid one time password.

Note: Email tokens do not work for connecting with any VPN.

Window for Entering the OTP.

The connection should now have been established successfully. You can stop your connection at any time by selecting Disconnect.

last changed on 08/14/2026

How did this content help you?

(opens in new tab)
This work is licensed under a Creative Commons Attribution - Share Alike 3.0 Germany License (opens in new tab)