Version Affected: All
Overview
Users are unable to authenticate through the SecureAuth RADIUS Server. There are several common configuration issues that can cause this — these causes are not related, so a fix for one cause will not resolve the other.
- See Cause 1 - The RADIUS client's IP address is not in the RADIUS Clients list
- See Cause 2 - The shared secret does not match between SecureAuth and the RADIUS client
- See Cause 3 - Windows Firewall is blocking the RADIUS authentication port
In this article
- Cause 1: RADIUS Client's IP Address Not in the RADIUS Clients List
- Cause 2: Shared Secret Mismatch
- Cause 3: Windows Firewall Blocking the RADIUS Port
Cause 1: RADIUS Client's IP Address Not in the RADIUS Clients List
For the SecureAuth RADIUS Server to trust a device (such as a Cisco ASA or another network device) sending it authentication requests, that device's IP address must be added to the RADIUS Clients list.
Resolution 1:
- On the SecureAuth appliance, open a browser to http://localhost:8088/configuration.
- Confirm the IP address of the interface that connects to the RADIUS Server is listed under RADIUS Clients. If it is not, add it and click Save.
Cause 2: Shared Secret Mismatch
If the shared secret configured on the SecureAuth RADIUS Server does not match the shared secret configured on the RADIUS client, authentication fails with an error indicating the one-time passcode (OTP) is wrong, even when the correct code was entered.
Resolution 2:
- On the SecureAuth appliance, open a browser to http://localhost:8088/configuration.
- Confirm the Shared Secret value matches exactly what is configured on the RADIUS client's side.
Cause 3: Windows Firewall Blocking the RADIUS Port
The SecureAuth RADIUS Server uses UDP port 1812 by default for authentication. If this port is blocked by the Windows Firewall, a hardware firewall, or a router, authentication requests to the RADIUS Server time out and users cannot authenticate.
Resolution 3:
- Confirm UDP port 1812 (or whatever port is configured under Authentication Port in the RADIUS Server Settings above) is allowed through the Windows Firewall, any hardware firewall, and any router between the RADIUS client and the SecureAuth appliance.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.