How to configure Aventail for Radius Servers (e.g. SafeNet Cloud Authentication) deployed externall
03/26/2020 6 10789
How to configure Aventail for Radius Servers (e.g. SafeNet Cloud Authentication) deployed externally on the Internet
As per our admin guide the recommended way to setup Resources and Authentication servers is through the nternal Interface for Dual Interface Mode Deployment. In case you have your Auth-Server available on the internet (reachable via External Interface), then you might experience the following issue and to address it please refer the Internal Static route solution.
Aventail Appliances expects all the authservers to be communicated through internal interface. To support Authentication servers setup on the Internet, We need to add static routes to force the Authentication traffic via Internal interface thereby processing the Radius (or even AD/LDAP) authentication pass through the internal interface rather than the External interface.
In the system message info you can see the following errors when Aventail attempts Authentication via external Interface:
+ Error,12/24/13,14:19:05,Policy,10000054,Auth: CRAM-RADIUS: All attempts to contact RADIUS server failed. Please verify hostname/IP/port/secret in this realm and general networking settings.
+ Error,12/24/13,14:18:16,Policy,00000001,Auth: RADIUS-ACCT: All attempts to contact RADIUS server failed. Please verify hostname/IP/port/secret in this realm and general networking settings.
Aventail debug logging returns:
Error 1/6/14 15:13:07.280 Policy 100000b1 Unable to add session info to troubleshooting db for user 'test_user'.
Error 1/6/14 15:13:07.280 Policy 00000000 DBConnection: Error executing SQL statement -- error(MySQL server has gone away) sql(INSERT INTO sessionInformation (username,longUsername,licenseKey,remoteAddress,successfulAuthentication,xmlConfig,community_id,realm_id,zone_id,node_id,endTime) VALUES ('email@example.com','(test_user)@(testlocal.nl) (CN=test_user,OU=test,OU=test,DC=testlocal,DC=nl)','90CN=test_user,OU=test,OU=test,DC=testlocal,DC=nl:test_user','x.x.x.x','0','26','0','67','0','0',DATE_ADD(NOW(), INTERVAL 0 SECOND));)
Error 1/6/14 15:13:07.279 Policy 100000b1 Auth: CRAM-RADIUS: All attempts to contact RADIUS server failed. Please verify hostname/IP/port/secret in this realm and general networking settings.
Route populating RADIUS traffic on eth0 (internal interface) has to be added.
1. To add route go to: AMC > System Configuration>Network Settings>Routing>Static routes
IP Address | Netmask | Gateway
[RADIUS Public IP address] | 255.255.255.255 | [eth0 private IP address of the Aventail]
Administrator Guide for latest release to set RADIUS authentication server up.