cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1796
Views
0
Helpful
4
Replies

Cisco AnyConnect Multifactor authentication Failed on Conn profile

waqasrd_99
Level 1
Level 1

Hi,

We have setup AnyConnect MFA with Azure (using NPS extension). It is working fine with the test connection profile. But it failed on Prod Connection profile. Both using same LDAP user groups. NPS servers and policies are identical. User receives text code on mobile but does not get authenticated. Weirdly, user can complete authentication with Microsoft authenticator Application. Is there anything missing on Prod Connection profile or Group policies or Azure?

 

Thanks 

1 Accepted Solution

Accepted Solutions

waqasrd_99
Level 1
Level 1

Thanks for your support. Issue was actually with timeout settings of radius server on ASA set to 10 seconds. I changed to 30 seconds and now users can connect via text code and 

View solution in original post

4 Replies 4

>From ASA can you 'debug ldap' to see whether ASA is receiving successfull
authentication response after MFA or not. This way you narrow down you
troubleshooting. If ASA is not receiving correct response from NPS after
user put the code then you need to look at NPS.

***** please remember to rate useful posts

Hi Mohammad,

 

Thank you for your response. it is working fine on the test connection profile. We are using same NPS server and ldap user group for both. Unfortunately,  I cant debug because its in Production. I am keen to get root cause what could be wrong with Production connection profile? 

Debug ldap won't cuz load on ASA. Without debugs, we can't findout

waqasrd_99
Level 1
Level 1

Thanks for your support. Issue was actually with timeout settings of radius server on ASA set to 10 seconds. I changed to 30 seconds and now users can connect via text code and