Problem with Meraki AP MR18 Radius + MFA

bouboikoi
New here

Problem with Meraki AP MR18 Radius + MFA

Hello everyone,

 

We want to add the MFA to our Radius configuration. The server configuration is ready and the MFA module with Azure AD is operational.

We have created an SSID connected to the Radius server with MFA :

bouboikoi_0-1656340217275.png

 

When we try to connect to the WIFI on Windows 10 system, the connection is made, we receive an MFA notification, but we don't have time to validate the notification. Even when we manage to validate the notification, the authentication page closes and asks us for the credentials again.
The authentication page usually closes after 5 seconds.

When we try on the phone, we don't have the same behavior, we have a much longer time.

 

Here are our EAPOL parameters:

bouboikoi_1-1656340489030.png


For your information we have tried various combinations.
The EAPOL key timeout parameter is limited to 5000ms.

 

We have already tried to contact Meraki support without success and followed the procedure they sent us : Meraki process 
On your side, did you manage to get WIFI working with Radius + MFA?

 

Thank you in advance for your answers.

 

Best regards,

 

Florian

1 Reply 1
PhilipDAth
Kind of a big deal
Kind of a big deal

MFA doesn't work well on WiFi for the reasons you have given.  Even if you managed to authenticate quickly enough, you are likely to get prompted again every time you roam between access points.  You'll get prompted every time you walk in and out of range.

 

So scrap that approach and think about alternatives.

 

Perhaps if this is for corporate devices you could consider using WPA2-Enterprise mode with certificates.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels