<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo Authentication Proxy Manager Configuration in Deployment Strategy</title>
    <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206080#M242</link>
    <description>&lt;A href="https://duo.com/docs/authproxy-reference#radius-auto" target="_blank"&gt;https://duo.com/docs/authproxy-reference#radius-auto&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Radius_ip_1 is the IP or IP range of the boxes that are allowed to use the proxy as a radius server.&lt;BR /&gt;Radius_secret_1 is the secret that box will use.&lt;BR /&gt;&lt;BR /&gt;So if your switch has a management IP of 172.16.1.5,. that's the ip you put here.&lt;BR /&gt;&lt;BR /&gt;All of the various pieces are described on that page I referenced.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 09 Oct 2024 19:40:05 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2024-10-09T19:40:05Z</dc:date>
    <item>
      <title>Duo Authentication Proxy Manager Configuration</title>
      <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5205899#M241</link>
      <description>&lt;P&gt;I have a free trial for the Cisco DUO Admin portal, and I'm trying to setup the Authentication Proxy.&amp;nbsp; We have an Active Directory Server but not a RADIUS Server.&amp;nbsp; My understanding is that we don't need a separate RADIUS Server, since Duo will act as a Proxy, and we can use Active Directory.&lt;/P&gt;&lt;P&gt;We are trying to get some sort of 2FA working with network devices that will authenticate through a RADIUS Server, such as Linux Servers and Network Switches/Routers.&amp;nbsp; I haven't gotten the RADIUS authentication working yet.&amp;nbsp; We have an Active Directory Server and a separate Server running the DUO Authentication Proxy software.&amp;nbsp; These 2 Servers are in the same network and can ping each other, but the Authentication Proxy Server is not joined to the domain.&lt;/P&gt;&lt;P&gt;I have finished the configuration and when I validate the configuration, there are no problems found.&lt;/P&gt;&lt;P&gt;The main question I have is about the [radius_server_auto] section of the configuration file:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; For the 'radius_ip_1' entry, what IP is needed?&amp;nbsp; It's not very clear to me if this is supposed to be the IP of the Active Directory Server, Authentication Proxy Server, a completely separate RADIUS Server that we don't have, or something else.&lt;BR /&gt;&lt;BR /&gt;-I have tried entering different IPs; Active Directory Server or DUO Authentication Proxy.&amp;nbsp; I restart the Service whenever I make any changes.&amp;nbsp; So far, I have been unable to authenticate to the RADIUS Proxy.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 16:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5205899#M241</guid>
      <dc:creator>jeremy81</dc:creator>
      <dc:date>2024-10-09T16:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Authentication Proxy Manager Configuration</title>
      <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206080#M242</link>
      <description>&lt;A href="https://duo.com/docs/authproxy-reference#radius-auto" target="_blank"&gt;https://duo.com/docs/authproxy-reference#radius-auto&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Radius_ip_1 is the IP or IP range of the boxes that are allowed to use the proxy as a radius server.&lt;BR /&gt;Radius_secret_1 is the secret that box will use.&lt;BR /&gt;&lt;BR /&gt;So if your switch has a management IP of 172.16.1.5,. that's the ip you put here.&lt;BR /&gt;&lt;BR /&gt;All of the various pieces are described on that page I referenced.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Oct 2024 19:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206080#M242</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-10-09T19:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Authentication Proxy Manager Configuration</title>
      <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206095#M243</link>
      <description>&lt;P&gt;Are you following the steps in&amp;nbsp;&lt;A href="https://duo.com/docs/radius?" target="_blank"&gt;https://duo.com/docs/radius?&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;you need an [ad_client] section pointing to your AD DC (&lt;A href="https://duo.com/docs/radius#active-directory" target="_blank"&gt;https://duo.com/docs/radius#active-directory&lt;/A&gt;), and then as Ken suggests you put the info about the downstream RADIUS device in the [radius_server_auto] section (&lt;A href="https://duo.com/docs/radius#configure-the-proxy-for-your-radius-device" target="_blank"&gt;https://duo.com/docs/radius#configure-the-proxy-for-your-radius-device&lt;/A&gt;).&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 20:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206095#M243</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2024-10-09T20:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Authentication Proxy Manager Configuration</title>
      <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206138#M245</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp; Entering the IPs of devices allowed to connect makes more sense.&lt;BR /&gt;-Is it possible to enter an IP range or allow all, or anything like that, or is it individual IPs only?&amp;nbsp; What are the syntax options?&lt;BR /&gt;&lt;BR /&gt;I do have the [ad_client] section configured.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 22:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206138#M245</guid>
      <dc:creator>jeremy81</dc:creator>
      <dc:date>2024-10-09T22:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Authentication Proxy Manager Configuration</title>
      <link>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206153#M246</link>
      <description>Syntax options are in the link I sent earlier.&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Oct 2024 22:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/deployment-strategy/duo-authentication-proxy-manager-configuration/m-p/5206153#M246</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-10-09T22:59:05Z</dc:date>
    </item>
  </channel>
</rss>

