set admin-2fa

In the R81.10.X releases, this command is available starting from the R81.10.10 version.

Description

Enable/disable Two-Factor Authentication for all administrators to access the Security Gateway. All administrators must have both an email address and phone number configured. If any administrators are missing either an email address or a phone number, you cannot enable the feature. Once enabled, Two-Factor Authentication is required for all logins/access to the gateway.

Before Two-Factor Authentication is activated for the gateway, all administrators receive an email explaining how to use the Authenticator app. The email also contains a QR code and emergency keys. Confirm that you received the email or request to resend (yes/resend/quit). All administrators will receive an email containing instructions and their own keys.

See show admin-2fa.

Syntax

set admin-2fa { on | off }

Parameters

Parameter

Description

on

Two-Factor Authentication is enabled.

off

Two-Factor Authentication is disabled.

Example Command

set admin-2fa on