Security

 View Only
  • 1.  VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    Posted Aug 20, 2024 04:06 AM
    Edited by nktns Aug 20, 2024 04:12 AM

    Integration has been done based on this guide - Microsoft Azure Multi-Factor Authentication (MFA)

    General idea seems to be working - IKEv1/PAP is fine, but IKEv2/EAP-MSCHAPv2 is not connecting properly. If using local ClearPass user - VIA connects fine. If MFA request can be accepted successfully really quick (around  5 seconds or so) - connects sucessfully. But normally VIA times out with error -8980 and connection fails.

    Will not jump into troubleshooting logs, but I have a feeling VIA IPSec session times out before receiving RADIUS response. RADIUS timeouts have been tuned on controller/ClearPass side to 30 seconds, but is there anything that may have not been mentioned in the guide regarding timers? 

    AOS: 10.4.1.1

    CP: 6.10.8



  • 2.  RE: VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    Posted Aug 20, 2024 10:07 AM

    PAP is called out as the needed protocol to support all available methods.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    Posted Aug 20, 2024 10:20 AM

    Supported MFA methods wasn't the question, push notification is used and that is supported with EAP-CHAPv2 as per your screenshot.