RD Gateway with Azure Multifactor Authentication Dont Work - RADIUS Proxy received a response from server with an invalid authenticator
implemented rds lab 2 windows 2012 r2 servers:
- rd wa, rd gw , rd cb roles on rds-gw server (10.150.1.11)
- rd sh on rds-sh server (10.150.1.12)
no mfa authentication, rdweb access work well. when connect via rdweb test account , open remoteapp, rd gw verify cap policy, authenticate user verify rap policy , finaly app open.
next installed azure mfa server on rds-sh server implement multi-factor authentication. configured rd gw, nps , mfa servers following steps on http://www.rdsgurus.com/step-by-step-using-windows-server-2012-r2-rd-gateway-with-azure-multifactor-authentication/ (step step – using windows server 2012 r2 rd gateway azure multifactor authentication).
now, when connect via rdweb , open remoteapp, after aproximadly 10 seconds receive mfa call on phone, reply # rdweb continues showing waiting window “starting…” , remote app don’t open. after 1 minute rdweb show message error indicating can’t connect remote computer. meanwhile after first call continue receiving more 3 calls mfa service.
tested mfa directly on mfa server , works same test account used on rdweb access.
aparently rd gateway forwards radius request through nps mfa server mfa perform 2 factor authentication sequence user (via phone call in case). user reply, mfa server apparently don’t send accept rd gateway expected.
firewalls on rds-gw , rds-sh server disabled. rds-gw server shows 4 times nps event id 28 “the radius proxy received response server 10.150.1.12 invalid authenticator.” , 1 time nps event id 38 “the remote radius server 10.150.1.12 has not responded 5 consecutive requests. server has been marked unavailable.”.
can’t figure out why doesn’t work.
help?
hi jay,
the following solved problem: 1 – remove rd gw rds farm; 2 – uninstall rd gateway role service; 3 – re-add rd gw on rds farm , configure (install certificates, configure cap , rap policies central server running nps); 4 – reinstall mfa server on same vm (rds-sh).
note: used have error “rd gateway: following error(s) occurred: unable update ias server configuration current configuration maybe in inconsistent state” when changing ip , shared secret of mfa server on option “central server running nps” (in rd gw manager). after reinstallation error gone.
best regards,
jg
Windows Server > Remote Desktop Services (Terminal Services)
Comments
Post a Comment