SSL VPN Radius with 2factor timout

In Sophos XG, is there any way to increase the timeout for radius servers?

I'm having problems using SSL VPN authentication with radius when using 2-factor. If I bypass 2factor, I'm logging in fine.

If I enable 2factor, it seems to timeout and I get a second credential prompt before I get to accept the first request, rendering my first request invalid.

I've seen this question before and the answer was that the timout is hard coded. However that was a old thread:

http://feature.astaro.com/forums/17359-utm-formerly-asg-feature-requests/suggestions/2812151-authentication-configurable-radius-timeout

Maybe things have changed?

  • Do you have any updates regarding this problem, I'm facing the same with Microsoft Multi-Factor Authentication Server
  • In reply to BalazsZeller:

    Sadly not yet, just recieved my ordered hardware appliance but non-working 2-factor authentication is kind of a dealbreaker for me. I really like Sophos and what they do so I hope there is a solution for this.
  • In reply to AndrzejSydorko:

    Hi,
    I received a clue that the new XG firmware will include the 2FA solution from the Sophos UTM series, but I hope that they have the solution for our problem.
    Currently I'm really sad because I made a support ticket and they have "forgotten" to say anything for 1 weeks now....
  • I upgraded to v16 today as I was excited like a child about the news that it's been released.

    It wasn't really straight forward, I hade to download and install the latest beta first to get it to see the GA update.

    After the upgrade I was eager to try out 2fa so I activated it on my radius server once again.

    To my horror 2fa failed again.

    I got the authentication request on my phone but before I had time to accept it, the ssl vpn client disconnected, timing out as usual.

    If I'm really fast, I meen really really ready, with the 2fa app open and my finger hoovering over the phone, I sometimes manage to authenticate before it times out !

    I'm guessing there still isn't any way to increase the radius timeout on the XG?

    Oh and I'm pretty sure its the XG, not the vpn client that is the issue as I 'm getting timeouts on the user portal as well.

     

    Please sophos, you have to get this done right and soon, I have clients waiting for this stuff to work!

     

  • In reply to AndrzejSydorko:

    Hi Andrzej,

    Bit of an interesting one, what 2FA provider are you using?

    I'm not sure the XG has a configurable timeout and that feature request was for the SG UTM, not the XG so it may not be following it through.

    Emile

  • In reply to EmileBelcourt:

    Hello Emile

     

    I'm using Duo, but I guess anything that delays the authentication reply the slightest will result the same.

    Typically it takes 5-7 seconds from the moment I press login in the client till I press accept on my phone.

    We use Duo a lot and I'm really hoping Sophos will get this together.

    I really like the XG but I'm not going to recommend a UTM without working 2fa to my clients.

    Not being able to set a timeout for radius is just silly, especially when it seems to be so short per default.

    The model we use is pretty common I think:

    router->radius->2fa mechanism

    It just has to work, the people demand it.

     

    I've been playing with the clients config this evening adding higher timeout values to available parameters but that didn't help...

  • Hi Andre,

    The feature to configure access server timeout is considered in the ID NC-8393. It will be added in the future firmware releases.

    Thanks

  • In reply to sachingurung:

    That is wonderful news.

    Digging trough the net in search for answers, it seems this has been on the wishlist for a long time, even pre-XG.

    Now the interesting question is when will it be released? Any idea?

     

     

  • In reply to AndrzejSydorko:

    I was the one that started the 1st thread, this is good news.

  • In reply to sachingurung:

    Hello, can you please provide an update regarding ID NC-8393?  Is there a method for implementing a RADIUS timeout for out-of-band services such as Duo via shell?

    Thank you.

  • In reply to GuidoGarcia:

    Guido,

    If there is a nic opened, the feature is completely missing even from CLI.

    Hope they will give us when this will be implemented v16.5, v17....

  • In reply to lferrara:

    This is now a very important requirement from a compliance perspective.  If I cannot get an answer on this, I may very well have to look at alternative solutions.

    Are there an updates?  I'm not sure how out-of-band radius authentication scenarios have not been considered.

  • In reply to sachingurung:

    What's the current status of NC-8393? When can we expect to see it in a release?

  • Hi there, are there any new informations about the radius timeout issue? We like to use Microsoft mfa an in the case that the Primary 2factor Fails the radius Connection will droped from the xg Firewall wile MS mfa tries to use the alternate 2 factor (SMS or phonecall for example). 

     

    Best regards, 

    Stefan

  • In reply to sachingurung:

    Please provide an update on this. It seems many of us are facing the same challenges and the only options are to change MFA provider or reduce our VPN security (neither of which are ideal).