This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

MFA Radius for Admin on Switches etc

Hi All,

Hoping someone can help as I'm stuck trying to get MFA Radius auth to work for Admin access on switches etc.

AAuth 6.4.1
I'm trying to use Radius with MFA for Admin access to switches etc. Can't get the rules/chains, just getting auth-reject, with various errors in the radius log depending on what I change to try and get it working. I have read the doco many times, and watched a few videos on it but cannot get it to work. Using an Authenitcator app to get the 6 digit OTP which is appended to the password during the connection attempt.... ie User-Name mcurrie User-Password Passw0rd764733 where 764733 is the OTP.. I think I have the rules regex correct, but not sure on the rest or the placement of Event-->Radius Server vs Policies-->Radius Options..I'm a bit stumped to be honest, maybe Fridayitis??.. Please assist if you can as it will be driving me bat crap crazy all weekend if I don't solve it.

Thanks in Advance.

  • 0  

    Hi Mark,

    I see you have opened a ticket with support, that is the best way to get help as the engineer may need to do a remote session and help you during the configuration, check logs, etc.

    Let us know if you need any help with this interaction with TS.

    Thanks.

    Regards,

    Luciano Testa

  • 0 in reply to   

    Hi Luciano, Thanks, can you please pick up the ticket, I have serious doubts about the ability of the frontline dealing with AA, he seriously suggested to me that the fix for an invalid password is to put in the correct password...Regards, Mark Currie

  • 0   in reply to 

    Hello Mark,

    I am looking into it now.

    Let me see what I can do about the issue.

    Thanks.

    Regards,

    Luciano Testa

  • 0 in reply to   

    Hi Luciano,

    This issue is largely solved, in that I have it working with NTRadPing, but the switches are bouncing the connection as the required radius arribute is not being returned. (I just posted a new community post on this).

    Basically solved by rereading the doco 25k times (which really did little to help), and using brute force configs until i found the combo which worked. lol.

    Thanks,

    Mark Currie

  • 0   in reply to 

    Thanks Mark. I am glad you were able to make it work.

    AAF uses FreeRADIUS underneath, so perhaps it makes sense to trust the documentation and examples from that source.

    Thanks.

    Regards,

    Luciano Testa