- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-15-2021 09:37 AM - edited 10-15-2021 09:38 AM
Hi Folks,
We are trying to configure MFA under Radius using Cisco DUO.
We have done the configuration for MFA in firewall for the same.
Now we are facing some problem such as 'Reason: Invalid username/password. auth profile \'Duo_Auth\', vsys \'vsys1\', server profile \'Duo_Radius\', server address Failed to communicate with any Active Directory server\' From: x.x.x.x'
This is the error coming in system log.
Also when we tried to login with CLI using test authentication authentication-profile auth-profile username & passwork.
We received this below error message.
Target vsys is not specified, user "username" is assumed to be configured with a shared auth profile.
Do allow list check before sending out authentication request...
name "username" is in group "all"
Egress: No service source route is set, might use destination source route if configured
Authentication to RADIUS server at x.x.x.x:1812 for user "Username"
Authentication type: PAP
Now send request to remote server ...
Authentication failed against RADIUS server at x.x.x.x:1812 for user "Username"
Authentication failed for user "Username"
What could be the cause here let me know what could be done next.
Cheers
10-15-2021 02:04 PM
Hi @Vijaygvasan ,
You mentioned RADIUS. Have you configured the Duo Authentication Proxy? Here is a doc for GP, but the RADIUS config is the same regardless of the use case. https://duo.com/docs/paloalto
Here is an overview of supported use cases and protocols for PANW MFA. https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.h... Note that the MFA server profiles can only be used with the Authentication Policy for now.
Thanks,
Tom
10-16-2021 12:10 AM
Could you please share any methods or documents to use Authentication policy using MFA.
Or some steps would be fine for that.
Cheers
10-16-2021 07:28 AM
Hi @Vijaygvasan ,
Sure! Here is a doc -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HANzCAO&lang=en_US%E2%80%A.... That doc uses an MFA server profile.
With PANW and Duo, there are 4 ways to configure MFA:
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!