Hello
We are running duo 2fa for accessing our vpn and occasionally some users never receive the push but Cisco Secure connect get them into vpn normally.
We use duo proxy server and Firepower 1140 with FMC. both are located in the same network in a colocation datacenter.
AD is located in another local site being accessed with site2site vpn.
We have the same setup on premise for accessing vpn as well and it works flawless. duo proxy, firepower, fmc and AD are located onpremise.
We used to use vpn.domain.com to login with Cisco Secure Client using the setup onpremise but we migrated everything to colocation
and now we use vpn-c.domain.com using the setup in colocation. But we keep the onpremise vpn for backup.
We also tried to use an AD in AWS also through site2site from our colocation datacenter but still the problem remains.
The only difference between the two setups is the AD. In onpremise setup AD is local and on the colocation it is remote (onpremise).
i have the duo proxy log but i cannot and see understand where and if it mentions that duo push was not received but the user logged in successfully.
Thank you
What would you recommend checking? have you deal with it before?