cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1376
Views
0
Helpful
7
Replies

Anyconnect disconnects if I don't press the accept button of DUO in the mobile

Hello, 

 

I have a pair of FTD 2110 in HA. The authentication is through ARUBA and DUO. 

The problem I have is this. I logon to the VPN and then I have to press accept from the mobile. If I do not accept immediately then Anyconnect disconnects and then multiple requests come to ARUBA and DUO. 

 

The retry interval in the radius server is max 10 seconds. Is there any way to extend another timer so I have a user-friendly

experience?

 

Thanks and regards, 

Konstantinos

7 Replies 7

Hi,
Under the RADIUS Server configuration (on the FTD) you need to extend the timeout for each RADIUS server, 60 seconds minimum is recommended.

HTH

Hi Rob,

Thanks for the prompt answer.
I have tried that but it did not change something.
I have one RADIUS server.

What is configured as the RADIUS server? Aruba or DUO? If you are proxying DUO through Aruba, then define a timeout on Aruba RADIUS server aswell.

If not please provide screenshots.

For Radius I use the Aruba.
So in the FTD you suggest extending the timeout in both servers, right?
Or you are talking about the actual aruba server?

Configure the timeout on the Aruba Clearpass server, under the configuration of Duo radius proxy.

Hello,

On Aruba, I went to Authentication->Sources->Radius
The server timeout is 30 sec.
Is this what you are referring to?

What is the point of changing it if in the FMC the retry is 10 sec?

Thanks and regards,
Konstantinos

You are using the Aruba to proxy the request to the Duo Proxy server. So the FTD will waiting for a response from Aruba Clearpass, which in turn is wiating to recieve a response from the Duo Proxy. Align the timeouts on all devices.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: