Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Radius Authentication for MFA (Multi-Factor Authentication) applications

2025-02-24 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Servers >

Share

Shulou(Shulou.com)06/03 Report--

Last time introduced the ExchangeOWA to enable MFA multi-factor authentication, today introduced the next, through the MFA RADIUS to achieve multi-factor authentication!

For the process of installing and enabling MFA, importing AD accounts, setting phone numbers, and language options, please refer to steps 1-14 in the previous article (https://blog.51cto.com/hubuxcg/2068870). Here we only introduce the configuration part of Radius.

1. Enable the Radius function in MFA

2. Add the device IP, device name and shared password that require RAIDUS authentication, and check the box that requires multi-factor authentication.

3. Select the target: Windows Domain, that is, to authenticate the user from the Windows domain

4. After the MFA configuration is completed, modify the Radius authentication configuration on the × × × device. Take CISCO ASA as an example, add the Radius server group first.

5. Add Radius authentication server

6. Specify the server name or IP address, that is, the IP address of the installed MFA server, the shared password (the password configured in the second step), and save it after configuration.

7. After the server-side configuration is completed, start × × connection verification, enter the user name and password, and then start to verify the login information.

8. Here you need to wait for phone verification. The phone you set up earlier will receive a call from a strange number. If you don't answer it or hang up, × × dialing will prompt you to fail to verify and disable login!

9. If you connect normally, press the # key according to the voice prompt to verify (or PIN code)

10. If you pass the verification, you can connect normally!

11. Because the verification time will increase after adding multi-factor verification, and the default 10 seconds will not be enough, it is recommended to increase the Timeout time of Radius to 30 seconds, or adjust it according to the situation.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Servers

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report