07-28-2020 08:18 AM - edited 07-28-2020 08:19 AM
Need some help to shed some light on the below errors.
I have Okta for MFA set up as an external radius server on ISE (i think here lies my problem, as other users on here have mentioned configuring Okta as radius token instead). I'll try radius token, but for now Okta is currently set up as an external radius server on ISE and I get an access reject back from Okta with the following error seen in the ISE radius live logs: "Authentication failed for user user@company.com, reason --- Access-Request failed, error: Request failed at step=DURING_MFA_POLL_LOOP. Time-out".. Anyone know what this MFA_POLL_LOOP timeout is?
In other instances I see this error in the live logs: "5405 RADIUS Request dropped - 11353 No more external RADIUS servers; can't perform failover"
Solved! Go to Solution.
07-28-2020 11:53 PM - edited 07-28-2020 11:56 PM
I was able to get this working setting up Okta as a RADIUS Token Server on ISE. Not sure why RADIUS proxy doesn't work, must be the Okta side.
11-08-2021 08:40 AM
Please follow one of the existing guides, that also use RADIUS token servers.
For example, How to Deploy ISE Device Admin with Duo MFA
07-28-2020 11:53 PM - edited 07-28-2020 11:56 PM
I was able to get this working setting up Okta as a RADIUS Token Server on ISE. Not sure why RADIUS proxy doesn't work, must be the Okta side.
11-05-2021 12:43 PM
Hi Madura Malwatte,
I am trying to Add OKTA to ISE 3.0 as Radius Token server
I want to use OKTA for authentication on Device Admin and use AD for Authorization
Can you please me with some reference document or share some Steps/Screenshots ???
11-08-2021 08:40 AM
Please follow one of the existing guides, that also use RADIUS token servers.
For example, How to Deploy ISE Device Admin with Duo MFA
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide