Supported way to use MFA to BIG-IP GUI and shell
I have read on DevCentral various mechanisms to implement 2FA (MFA) using APM and even some packages to change the PAM and implement this on the SSH shell.
Are there any supported mechanisms to protect the BIG-IP Web interface via multi-factor? Even if one had the APM, can it be turned around to control the BIG-IP GUI itself?
Also, what about SSH access?
I am curious if others have solved this issue. It is surprising to me that at least the GUI does not have a native MFA solution to basic administration.