Forum Discussion
Yashwardhan_Pra
May 18, 2011Nimbostratus
FirePass VPN: "STATE" attribute issue with second factor authentication (Access-Challenge mode)
Hi,
When Validation Server is running in Access-Challenge mode, it validates the username, password sent in the first radius request. If the provided username, password provided in the first radius request is valid, then radius access challenge will be thrown to the client. Radius Access challenge message will have ‘STATE’ attribute as per RFC.
When client responds to radius Access-Challenge, it should include the “STATE” attribute value which it received in Access Challenge message.
Current firepass vpn is not including the “STATE” attribute in second radius request which is it received as part of radius Access-Challenge packet.
Because of this Validation Server is treating the second radius request as one having username and LDAP password.
Has anyone observed this issue earlier? Is there any solution for this?
Please reply back ASAP.
With Regards,
Yashwardhan Pradhan
- Mike_61719CirrusI would talk to support about this issue. What version of Firepass are you running?
- Yashwardhan_PraNimbostratusHi Mike,
- Yashwardhan_PraNimbostratusHi Mike,
- Yashwardhan_PraNimbostratusHI F5 TEAM,
- Yashwardhan_PraNimbostratusHI F5 TEAM,
- Yashwardhan_PraNimbostratusHI F5 TEAM,
- Yashwardhan_PraNimbostratusHI F5 TEAM,
- Mike_61719CirrusPosted By Yashwardhan Pradhan on 06/02/2011 10:54 PM
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects