This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Converting from LDAP to Radius Authentication for DUO MFA with Sophos SSL-VPN

We were testing DUO MFA with LDAP authentication to our Active Directory using the Sophos SSL-VPN.  Tan into the "timeout" problem and created a Radius login and server to fix this.   Now we are seeing: 

1. Initial validation appears to work,   

2. DUO MFA request is sent to the phone for authentication .

3. Once returned, the authorization fails at final login. 

I'm wondering if this is because of something changed in the way groups our handled?  

All users are members of our AD Group "VPN Users

What's the missing link?   


Thanks.   



This thread was automatically locked due to age.
Parents Reply Children
  • Hi....JasP....yes your "3-ways... article" was really helpful, and we originally had switched to what I believe was your preferred option; using the DUO RADIUS server configuration with an ad_client section for authentication. This appeared to work fine as far as the DUO MFA,  but then when DUO returned the authorization it appeared that there was change in the username and/or domain from the original  username.  This was finally resolved by making a change to the domain name parameter in our Radius Config on the XG.  It now appears to work as expected, and tests with a half-dozen users so far suggest that it is solid. We're in the process of rolling out to additional users and will see how it performs under load. Many thanks for all your help.   

  • I'm glad you found it useful and thanks for the feedback. It was a fair bit of work so its always good to hear that someone found it helpful.