VPN: Using Duo Append Mode with Cisco AnyConnect

Certain Departmental Pools, Full Tunnel VPN, and Split Tunnel VPN Pools require Two-Factor Authentication (2FA) through Duo Security to connect

Since the Cisco AnyConnect application does not allow you to choose your authentication method using Duo Prompt, you can use the Duo Append Mode

Append Mode by default sends a push notification to your default device, but also allows you to choose from the following options:

Using Duo with Cisco AnyConnect

  1. Launch the Cisco AnyConnect Secure Mobility Client. 
  2. Choose the desired VPN Pool from the drop-down menu and click Connect.
    • The available choices should be: 
      • UMN - Departmental Pools
      • UofM Full Tunnel
      • UMN - Split Tunnel - General Access VPN Pool
  3. A new window opens, prompting for your Username and Password.
    • Username: Your UMN internet ID
    • Password: Your UMN password
  4. To use the default authentication method (a push to your default device):
    • Enter your information and click OK. A Duo Security push will automatically be sent to your default Duo device.
  5. For any other method for authentication, use the table below.
  6. With successful authentication, the Cisco AnyConnect application displays the message Connected to [VPN Pool] at the top of the screen. 
  7. To disconnect and end the connection, click Disconnect.
This table outlines the Duo Append Mode choices, shows specific examples, and outlines the intended action.
 Type Example  To...
passcode password,123456 Login using a passcode generated in Duo Mobile, by a token, or generated Bypass Codes.
push

password,push

password,push2

Push a login request to your device of choice.
phone

password,phone

password,phone3

Authenticate with a phone call back to your phone of choice.
  • When completing the password field with an additional option, you will enter your password plus a keyword from the table.
    • Note: Make sure to add the comma between the password and keyword with no additional spaces.
    • Example: UMN Password,phone
  • If you have multiple devices registered, you may add a number at the end of the keyword to select the desired device. Examples:
    • push2 sends a push request to the second phone in your list of registered Duo Devices
    • phone3 calls the third phone in your list of registered Duo devices.
TDX ID
3511