1. Login into the Pfsense admin portal
    2. Go to "Services" -> FreeRADIUS" -> "Users" -> "ADD"
    3. Enter the user name (Case Sensitive)
    4. No need to enter the password
    5. Enable "One-Time Password" 
    6. Change OTP Auth Method to "Google-Authenticator" 
    7. Click the " Generate OTP Secret"
    8. Enter a PIN code of your choosing
    9. Generate QR Code
    10. You can provide the user the QR using Screenshot or provide the "Init-Secret"
  •  

    1. Go to "OpenVPN" - "Client Export" and scroll to the bottom of the page
    2. Download the "Inline configuration: Most Clients" 
    1. Go to the website OpenVPN Connect - VPN For Your Operating System | OpenVPN and download the client.
    2. Install the Client on the endpoint. 
    3. Upload the configuration you downloaded in step 12
    1. Change  the Profile name to a relevant name such as <Company - HQ>
    2. Add the username you just created
    3. Don't save your password
  •  

    1. When you are ask to enter a password enter the following <PIN><OTP>
  •  

    You should see a successful connection