Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
kamilazat
Advisor

EnableBlankRadiusAuth and OTP prompt

Hello everyone.

We're testing a scheme where a Windows user would only enter username and then authenticate with a mail OTP from radius server. This is the first time we're going through something like this and I'm a bit confused. So let me try to describe what we did so far and maybe you can direct me to the right direction.

First I set up Multiple Login Options:

1.png

And then I configure Authentication factor for RADIUS. Here I clear the checkbox "Ask user for password" so that the user would only provide his username and then is only asked for the OTP he receives via email:

2.png

Now, in Endpoint Security on the user PC, user enters his username and clicks connect:

3.png

The password prompt is greyed out (as in the image above) or completely nonexistent (below):

4.png

At this point gateway sends the Access-Request only when anything is entered. We tried entering the OTP code received by email and random characters. In all cases the connection gets reset.

I found this post, and tried sk167118 but when EnableBlankRadiusAuth is set to 1, we don't even see the "Response" prompt. When we set the RADIUS server's policy to use OTP from the mobile app, everything works fine, the problem seems to be with email. And there are no issues with the connectivity between the gateway and the RADIUS server.

Edit: I should've mentioned that EnableBlankRadiusAuth is still set to 1, but probably needs to be set back to 0. I'm not sure exactly what this does, though.

I'm sure there's some confusion at some point but we couldn't pinpoint where it is so far.

All help and ideas will be appreciated, as always 🙂

 

Cheers!

 

0 Kudos
4 Replies
G_W_Albrecht
Legend Legend
Legend

Open SR# with CP TAC to get this resolved asap !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
kamilazat
Advisor

@G_W_Albrecht Thanks for the recommendation. That will happen anyway if I can't find any answers 🙂

But before doing that, I still want to ask. Would you think it's the RADIUS server if everything works with mobile OTP but fails with mail OTP? Or is it possible for CP to have issues somewhere?

 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

I have no idea at all ! Maybe an issue with the email server...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

As far as I know, the only supported way to use RADIUS for MFA is to use a single prompt (user password + OTP on the same line).

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events