Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP Over IPSEC, Radius Authentication Failed

Hi, I'm trying to authenticate users using Radius server, I've set up everything according to the Knowledge Base which is here: How to use RADIUS Authentication: Astaro Security Gateway/Sophos UTM

the connection to the server is working



But When I test it I get this error



Radius Server Settings:








This is what I got from the Log File:

2014:11:02-11:23:32 HQ-sutm-h01-lab1 aua[11409]: id="3006" severity="info" sys="System" sub="auth" name="Bind test successfull. Method: radius"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Bind test request: radius"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Bind test successfull. Method: radius"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test request: m:radius, f:l2tp, u:abdul, ip:0.0.0.0"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test failed: Radius authentication failed"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test request: m:radius, f:l2tp, u:abdul, ip:0.0.0.0"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test failed: Radius authentication failed"
2014:11:02-11:23:32 HQ-sutm-h01-lab1 aua[11409]: id="3006" severity="info" sys="System" sub="auth" name="Bind test successfull. Method: radius"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Bind test request: radius"
2014:11:02-11:23:52 HQ-sutm-h01-lab1 aua[11433]: id="3006" severity="info" sys="System" sub="auth" name="Bind test successfull. Method: radius"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test request: m:radius, f:l2tp, u:abdul, ip:0.0.0.0"
2014:11:02-11:27:27 HQ-sutm-h01-lab1 aua[11732]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test failed: Radius authentication failed"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Spawned child for authentication test"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test request: m:radius, f:l2tp, u:abdul, ip:0.0.0.0"
2014:11:02-11:36:45 HQ-sutm-h01-lab1 aua[12612]: id="3006" severity="info" sys="System" sub="auth" name="Authentication test failed: Radius authentication failed"


This thread was automatically locked due to age.
Parents
  • I'm no MCSE, but it looks like the issue is:
    Authentication Type: PAP
    EAP Type: -

    The UTM will use PEAP, and I seem to remember that there are some times when you need to check PAP.  Any luck with those?

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I'm no MCSE, but it looks like the issue is:

    The UTM will use PEAP, and I seem to remember that there are some times when you need to check PAP.  Any luck with those?

    Cheers - Bob


    I've Highlighted the problem, Its using the wrong policy, how can I change it the correct one?

    Authentication Details:
    Connection Request Policy Name: Use Windows authentication for all users
    Network Policy Name: Connections to other access servers
    Authentication Provider: Windows
    Authentication Server: ***********
    Authentication Type: PAP
    EAP Type: -
    Account Session Identifier: -
    Logging Results: Accounting information was written to the local log file.
    Reason Code: 66
    Reason: The user attempted to use an authentication method that is not enabled on the matching network policy.
Reply
  • I'm no MCSE, but it looks like the issue is:

    The UTM will use PEAP, and I seem to remember that there are some times when you need to check PAP.  Any luck with those?

    Cheers - Bob


    I've Highlighted the problem, Its using the wrong policy, how can I change it the correct one?

    Authentication Details:
    Connection Request Policy Name: Use Windows authentication for all users
    Network Policy Name: Connections to other access servers
    Authentication Provider: Windows
    Authentication Server: ***********
    Authentication Type: PAP
    EAP Type: -
    Account Session Identifier: -
    Logging Results: Accounting information was written to the local log file.
    Reason Code: 66
    Reason: The user attempted to use an authentication method that is not enabled on the matching network policy.
Children
No Data