Troubleshooting: Common RADIUS Authentication Failures

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Users are unable to authenticate through the SecureAuth RADIUS Server. There are several common configuration issues that can cause this — these causes are not related, so a fix for one cause will not resolve the other.

    • See Cause 1 - The RADIUS client's IP address is not in the RADIUS Clients list
    • See Cause 2 - The shared secret does not match between SecureAuth and the RADIUS client
    • See Cause 3 - Windows Firewall is blocking the RADIUS authentication port

     

    In this article

     

    Cause 1: RADIUS Client's IP Address Not in the RADIUS Clients List

    For the SecureAuth RADIUS Server to trust a device (such as a Cisco ASA or another network device) sending it authentication requests, that device's IP address must be added to the RADIUS Clients list.

    Resolution 1:

    1. On the SecureAuth appliance, open a browser to http://localhost:8088/configuration.

    RADIUS Clients configuration page, listing a client IP address and its Authentication Flow Type, with an Add new client button.

    1. Confirm the IP address of the interface that connects to the RADIUS Server is listed under RADIUS Clients. If it is not, add it and click Save.

     

    Cause 2: Shared Secret Mismatch

    If the shared secret configured on the SecureAuth RADIUS Server does not match the shared secret configured on the RADIUS client, authentication fails with an error indicating the one-time passcode (OTP) is wrong, even when the correct code was entered.

    Resolution 2:

    1. On the SecureAuth appliance, open a browser to http://localhost:8088/configuration.

    RADIUS Server Settings page, showing the Shared Secret and Authentication Port fields under RADIUS Server Settings, and IdP Server, API Realm, API Application ID, and API Application Key under SecureAuth IdP Settings.

    1. Confirm the Shared Secret value matches exactly what is configured on the RADIUS client's side.

     

    Cause 3: Windows Firewall Blocking the RADIUS Port

    The SecureAuth RADIUS Server uses UDP port 1812 by default for authentication. If this port is blocked by the Windows Firewall, a hardware firewall, or a router, authentication requests to the RADIUS Server time out and users cannot authenticate.

    Resolution 3:

    1. Confirm UDP port 1812 (or whatever port is configured under Authentication Port in the RADIUS Server Settings above) is allowed through the Windows Firewall, any hardware firewall, and any router between the RADIUS client and the SecureAuth appliance.

     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.