cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
362
Views
0
Helpful
2
Replies

MFA on SSL via Cisco Duo

dkhurana
Level 1
Level 1
Current Configuration: We have Radius Server configured in our Active Directory machine, which is also used in FortiGate as Radius Server, where users are authenticated in FortiClient. 
 
In Cisco Duo, All computers are configured to use MFA for windows login via Active directory sync.
 
Issue: I want to integrate MFA in SSL VPN, while user's login in FortiClient. I'm using Radius client as my primary authenticator.  While validating the config in Duo Proxy, I have this message:
 
warn: We cannot confirm that the Auth Proxy was able to establish a RADIUS connection to 10.10.10.6:1812. In the case of an actual failure this may be due to a misconfigured secret or network issues. This may also happen if the upstream RADIUS Server does not support the Status-Server message
 
error: Connectivity validation was not successful
 Screenshot 2024-06-08 072309.pngScreenshot 2024-06-08 072410.pngScreenshot 2024-06-08 072934.pngScreenshot 2024-06-08 090307.png
2 Replies 2

ammahend
VIP
VIP

I don’t work with Fortinet much but have you looked at duo documentation 

https://duo.com/docs/fortinet

 

-hope this helps-

ccieexpert
Level 1
Level 1

Its documented here: https://duo.com/docs/fortinet

the pre-shared key needs to match both sides (proxy and fortigate)....

Please follow this document and if you are still having issues, then i suggest getting logs/debugs from the auth proxy.

https://help.duo.com/s/article/1126?language=en_US