
GregH.00578 (Customer) asked a question.
If we use Okta Verify as 2FA for our VPN access, what happens if we lose internet connectivity?
In a DDOS situation, we have specific groups that would require access to systems to mitigate the attack. How can they authenticate if our on prem VPN endpoint (which has a private backdoor) cant reach Okta on the internet?

Okta Verify OTP works offline. OTP is a clock-based algorithm that is synchronized with Okta.
I don't understand.
Our Okta Radius Agent is on-prem. Our VPN Endpoint asks for user creds, which fails in a DDOS situation as we can't get to [myorg].okta.com. We never even get to the 2FA.
Even when we set it up in a 'normal' situation (Agent can reach the internet), I can get the Okta Verify push using "password,PUSH", but how do I prompt for a OTP?