Skip to main content
kevinQMT
New Member
August 18, 2021
Question

VPN only client not working with Radius

  • August 18, 2021
  • 1 reply
  • 6649 views

We cannot seem to get the VPN only client working with our Radius setup on FG. Its setup this way for DUO push notices. VPN only client seems to look for an LDAP server, which is not used in our configuration. We attempted to switch the config to use LDAP instead of Radius but then DUO stops working.

This configuration works fine on the full FortiClient install but then timebombs after 30 days then only EMS connectsion are supported.

 

Has anyone else seen this?

 

[336] fnbamd_create_radius_socket-Opened radius socket 13 [336] fnbamd_create_radius_socket-Opened radius socket 14 [1391] fnbamd_radius_auth_send-Compose RADIUS request [1351] fnbamd_rad_dns_cb-x.x.x.x->x.x.x.x [1329] __fnbamd_rad_send-Sent radius req to server 'Duo RADIUS': fd=13, IP=x.x.x.x(x.x.x.x:1812) code=1 id=13 len=115 user="user" using PAP [313] radius_server_auth-Timer of rad 'Duo RADIUS' is added [743] auth_tac_plus_start-Didn't find tac_plus servers (0) [1015] __fnbamd_cfg_get_ldap_list_by_group- [1131] fnbamd_cfg_get_ldap_list-Total ldap servers to try: 0 [481] ldap_start-Didn't find ldap servers [596] create_auth_session-Total 1 server(s) to try [48] handle_rad_timeout-rad 'Duo RADIUS' x.x.x.x timed out, resend request.

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    August 18, 2021

    We have one customer using Duo. We set up a RADIUS for it and they said it's working. Only thing we had to adjust was remoteauthtimeout in global so that it won't time out before users finish the 2nd factor auth procedure on Duo side. So far the customer is not complaining after we've set it up and initially tested.

    kevinQMT
    kevinQMTAuthor
    New Member
    August 18, 2021

    the full client or the VPN only client? We have it working with the full client. I'll take a look but pretty sure we adjusted the remoteauthtimeout in global already. When using VPN only client get the MFA prompt and as soon as it is authorized we get the error. 

    Toshi_Esumi
    SuperUser
    SuperUser
    August 18, 2021

    We only deploy "FortiCliet VPN". None of our customers uses the EMS.