If users report that Cisco Duo 2FA fails when attempting to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device, and the VPN troubleshooting log in FMC shows an error indicating that the Cisco Duo AAA server has been marked as failed, the root cause is likely missing Duo trust certificates on the FTD device. Trust certificates are essential for establishing a secure and trusted connection between the FTD and the Duo authentication service. Steps: * Obtain the necessary Duo trust certificates. * Install the certificates on the FTD device. * Verify the configuration to ensure that the FTD device can properly communicate with the Duo AAA server. This resolves the authentication failure by ensuring that the FTD device can trust the Duo server. References: Cisco Secure Firewall Management Center Administrator Guide, Chapter on Certificate Management.