Enforce 2FA for VPN connections

Hi,

We have setup QBELT VPN and it is working fine.

We have also enabled 2FA for the VPN user accounts.

BUT although the users are prompted for 2FA - most of the time - and sometimes its quite delayed - they are still able to access network resources with the 2FA - sort of rendering it useless.

Is there a way to FORCE 2FA required for network access on the VPN?

Simon.

I’m joining the thread to fully echo your concerns. You’ve hit the nail on the head regarding a critical flaw in the current QBelt / QVPN 2FA implementation.

For small and medium-sized businesses (SMBs), this delay/bypassing of full 2FA enforcement before granting network access is a major security loophole. With the EU NIS 2 Directive taking effect, strict Multi-Factor Authentication (MFA) for remote access is no longer just a “nice-to-have” feature—it is a mandatory compliance requirement.

As it stands, having 2FA prompt asynchronously after or alongside network access sort of defeats the entire purpose of perimeter security. Given that QNAP already supports 2FA (like Google Authenticator) for web GUI logins, extending this as a strict, mandatory gateway check within the QVPN app and QBelt protocol shouldn’t be an impossible task.

We would really appreciate an official response from the QNAP team on this:

  1. Is there an active roadmap item to enforce strict pre-authentication 2FA for QBelt/QVPN?

  2. How does QNAP plan to help SMB users meet NIS 2 compliance requirements natively without forcing us to deploy external RADIUS or third-party Zero Trust architectures?

Looking forward to hearing QNAP’s stance on this!