cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

UDP Sessions Discarded (DUO timeouts)

L0 Member

Anyone experience any issues with 2FA timing out occasionally. For example, we have a weird situation where the 2FA integrated with DUO is working fine but after a week or two suddenly all users stop getting the push notification. Looking at the PAN logs, we see a discarded session and as soon as we clear that up, everything starts to work normal again.

 

The discarded session is between the server  and the PAN interface used as a radius source. So both of them are on the same zone. And the sessions are using port 1812 (UDP). The application on the session shows unknown udp

 

The packet captures simply show requests going to the server from the PAN and just getting timed out. 

 

Any clues?

Enterprise Security Architect, CCIE, PCNSE, CEH, CCSK
saad@mayfieldinc.net
Who Me Too'd this topic