300-710 · Question #345
Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device. IT staff have VPN profiles that do not require multifactor authent
The correct answer is D. Duo trust certificates are missing from the Secure FTD device.. If users report that Cisco Duo 2FA fails when attempting to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device, and the VPN troubleshooting log in FMC shows an error indicating that the Cisco Duo AAA server has been marked as failed, the root cause is likel
Question
Users report that Cisco Duo 2FA fails when they attempt to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device. IT staff have VPN profiles that do not require multifactor authentication and they can connect to the VPN without any issues. When viewing the VPN troubleshooting log in Cisco Secure Firewall Management Center (FMC), the network administrator sees an error that the Cisco Duo AAA server has been marked as failed. What is the root cause of the issue?
Options
- AAD Trust certificates are missing from the Secure FTD device.
- BMultifactor authentication is not supported on Secure FMC managed devices.
- CThe internal AD server is unreachable from the Secure FTD device.
- DDuo trust certificates are missing from the Secure FTD device.
How the community answered
(66 responses)- A3% (2)
- B11% (7)
- C5% (3)
- D82% (54)
Explanation
If users report that Cisco Duo 2FA fails when attempting to connect to the VPN on a Cisco Secure Firewall Threat Defense (FTD) device, and the VPN troubleshooting log in FMC shows an error indicating that the Cisco Duo AAA server has been marked as failed, the root cause is likely missing Duo trust certificates on the FTD device. Trust certificates are essential for establishing a secure and trusted connection between the FTD and the Duo authentication service. Obtain the necessary Duo trust certificates. Install the certificates on the FTD device. Verify the configuration to ensure that the FTD device can properly communicate with the Duo This resolves the authentication failure by ensuring that the FTD device can trust the Duo server.
Topics
Community Discussion
No community discussion yet for this question.