<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE problem with MFA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-problem-with-mfa/m-p/5202988#M592156</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Hope you are doing well.&lt;/P&gt;
&lt;P&gt;I have an interesting case that has been bothering me for over a month. Long story short - We did migration on customer ISE deployment from 2.7 to 3.2. Everything works correctly except VPN connection to customer network. We are using Firepower 4k as a VPN gateway. &lt;/P&gt;
&lt;P&gt;Scenario:&lt;/P&gt;
&lt;P&gt;External or internal users, it doesn't matter who wants to connect to the network via AnyConnect VPN.&amp;nbsp; User should enter the crendetials, receive an MFA notification (cuz we are using Microsoft MFA) and after confirmation gain access to the network. But some type of users receive additional notifications from Microsoft MFA even if they have already been connected to the network. For example 2-3 times gets another notification for allow from MFA after successful authentication. &lt;/P&gt;
&lt;P&gt;There are also some type of users who which do not reach the network at all, even if they receives a notification from the MFA and successfully authenticates according to it. Gets an error - specifically from the MFA log:&lt;/P&gt;
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI&gt;MFA denied; user did not respond to mobile app notification&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;MFA denied; duplicate authentication attempt&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I understand, MFA sends as many notifications as it receives requests from the radius server. The strange thing is that after switching the VPN to the old ISE, everything works correctly. B&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;oth new and old ISEs have an identical configuration. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I'm already solving it with TAC, but it's a bit stagnant at the moment, so I want to ask if anyone has encountered a similar scenario?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 14:13:09 GMT</pubDate>
    <dc:creator>Micinel</dc:creator>
    <dc:date>2024-10-03T14:13:09Z</dc:date>
    <item>
      <title>ISE problem with MFA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-problem-with-mfa/m-p/5202988#M592156</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Hope you are doing well.&lt;/P&gt;
&lt;P&gt;I have an interesting case that has been bothering me for over a month. Long story short - We did migration on customer ISE deployment from 2.7 to 3.2. Everything works correctly except VPN connection to customer network. We are using Firepower 4k as a VPN gateway. &lt;/P&gt;
&lt;P&gt;Scenario:&lt;/P&gt;
&lt;P&gt;External or internal users, it doesn't matter who wants to connect to the network via AnyConnect VPN.&amp;nbsp; User should enter the crendetials, receive an MFA notification (cuz we are using Microsoft MFA) and after confirmation gain access to the network. But some type of users receive additional notifications from Microsoft MFA even if they have already been connected to the network. For example 2-3 times gets another notification for allow from MFA after successful authentication. &lt;/P&gt;
&lt;P&gt;There are also some type of users who which do not reach the network at all, even if they receives a notification from the MFA and successfully authenticates according to it. Gets an error - specifically from the MFA log:&lt;/P&gt;
&lt;UL class="lia-list-style-type-disc"&gt;
&lt;LI&gt;MFA denied; user did not respond to mobile app notification&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;MFA denied; duplicate authentication attempt&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I understand, MFA sends as many notifications as it receives requests from the radius server. The strange thing is that after switching the VPN to the old ISE, everything works correctly. B&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;oth new and old ISEs have an identical configuration. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I'm already solving it with TAC, but it's a bit stagnant at the moment, so I want to ask if anyone has encountered a similar scenario?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 14:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-problem-with-mfa/m-p/5202988#M592156</guid>
      <dc:creator>Micinel</dc:creator>
      <dc:date>2024-10-03T14:13:09Z</dc:date>
    </item>
  </channel>
</rss>

