This depends heavily on the type of VPN you are using, and how it's configured. Typically, the Cisco AnyConnect VPN server will use HOTP/TOTP keys as a 'secondary_password' field — so you enter your username and normal password, *and* the One Time Password. The OpenConnect VPN client can automatically generate the response for that field, using the Yubikey.
But the number of possibilities is fairly much infinite. You could conceivably configure a VPN server to need *only* a Yubikey OTP response which both identifies and authenticates you. Or whatever you want. It's hard to answer a question which is so open-ended.
|