Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

This thread has been viewed 17 times
  • 1.  VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    Posted 20 hours ago

    Integration has been done based on this guide - Microsoft Azure Multi-Factor Authentication (MFA)

    General idea seems to be working - IKEv1/PAP is fine, but IKEv2/EAP-MSCHAPv2 is not connecting properly. If using local ClearPass user - VIA connects fine. If MFA request can be accepted successfully really quick (around  5 seconds or so) - connects sucessfully. But normally VIA times out with error -8980 and connection fails.

    Will not jump into troubleshooting logs, but I have a feeling VIA IPSec session times out before receiving RADIUS response. RADIUS timeouts have been tuned on controller/ClearPass side to 30 seconds, but is there anything that may have not been mentioned in the guide regarding timers? 

    AOS: 10.4.1.1

    CP: 6.10.8



  • 2.  RE: VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    EMPLOYEE
    Posted 14 hours ago

    PAP is called out as the needed protocol to support all available methods.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: VIA with Azure MFA and IKEv1/EAP-MSCHAPv2 timeouts

    Posted 13 hours ago

    Supported MFA methods wasn't the question, push notification is used and that is supported with EAP-CHAPv2 as per your screenshot.