11-29-2017 12:30 PM - edited 02-21-2020 10:40 AM
We're using radius, asa 9.6.x and windows 2012 nps. Our client is asking if there is any way to prove what authentication protocol is being used for anyconnect clients. I understand that PAP is being used by default and MSCHAPV2 is default when password management and or mschapv2-capable is used.
I did radius debug on the asa but it doesn't show what authentication protocol is used. Client checked NPS logs but they don't show protocol either.
Solved! Go to Solution.
11-29-2017 01:49 PM
Unless there is another smart way, you can run wireshark on the NPS server and see what comes in. Filter on radius packets and then drill down the authentication requests and check.
11-29-2017 01:49 PM
Unless there is another smart way, you can run wireshark on the NPS server and see what comes in. Filter on radius packets and then drill down the authentication requests and check.
11-29-2017 02:14 PM
11-30-2017 01:42 PM
Here's what I got from our client:
"Authentication Type in the NPS logs is just “Extension” which is referring to my Azure MFA NPS Extension"
We were able to get protocol via wireshark though. Thank you.
11-30-2017 01:46 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide