Cisco VPN MFA push timeout

Syafiq Hamid 60 Reputation points
2026-10-08T07:48:52.4333333+00:00

Hi Microsoft team

I am currently working with an on-premises Cisco VPN deployment that uses Duo MFA for user authentication. The VPN connection process generally works as expected, but we are running into an issue where the VPN authentication request appears to time out before users have enough time to respond to the Duo Push notification.

The environment consists of a Cisco VPN server integrated with RADIUS authentication and Duo MFA. In many cases, users receive the Duo Push notification, but the VPN session times out before they can approve the request, resulting in failed authentication attempts.

The specific concerns I am trying to address are:

  1. Users receive the Duo Push notification, but the VPN authentication process times out before approval is completed.
  2. Authentication retries appear to occur too quickly, causing the VPN session to fail even when users respond shortly afterward.
  3. I would like to understand whether the VPN server's RADIUS timeout and retransmission settings can be adjusted to better accommodate MFA response times.

I have reviewed the Cisco VPN and Duo configuration settings but have not been able to determine which timeout values should be modified or what the recommended settings are for this scenario.

Is there a approach for extending the RADIUS retransmit timeout or authentication timeout on a Cisco VPN server when using Duo MFA ?

Windows for business | Windows 365 Business
0 comments No comments

1 answer

Sort by: Most helpful
  1. Ronald Sabiiti 160 Reputation points Independent Advisor
    2026-10-08T08:13:35.65+00:00

    Hello @Syafiq Hamid

    Welcome to Microsoft Q&A!

    Thank you for your patience, and taking the time to elaborate on your concerns.

    Yes, you can extend the RADIUS timeout and retransmit settings on Cisco VPN appliances to better accommodate Duo MFA push response times. The recommended approach is to increase the RADIUS server timeout and reduce the number of rapid retransmissions so users have enough time to approve Duo Push before the VPN session fails.

    Key Cisco/Duo Settings.

    On Cisco ASA/AnyConnect VPN (RADIUS integration):

    RADIUS Server Timeout

    Default: 5 seconds

      Recommended with Duo: **30–60 seconds**
    
      
         Command (ASA CLI):
    
         
         bash
    
         
         ```sql
         aaa-server DUO-RADIUS protocol radius
    ```aaa-server DUO-RADIUS (inside) host <DuoProxyIP>
    timeout 60
             ```
             
    ```yaml
            This ensures the ASA waits long enough for Duo Push approval.
    
            
            **Retries**
    
            
               Default: **3 retries**
    
               
                  Recommended: **1–2 retries**
    
                  
                     Too many retries cause rapid re‑prompts and session failures.
    
                     
                        Command:
    
                        
                        bash
    
                        
                        ```sql
                        aaa-server DUO-RADIUS (inside) host <DuoProxyIP>
    ```retries 1
                            ```
                            
    **On Duo Authentication Proxy (**`authproxy.cfg`**):**
    
    Duo recommends matching the ASA timeout with the proxy’s `radius_server_auto` section.
    
    Example:
    
    ini
    
    ```yaml
    [radius_server_auto]
    ikey=YOUR_IKEY
    skey=YOUR_SKEY
    api_host=api-XXXXXXXX.duosecurity.com
    radius_ip_1=ASA_IP
    radius_secret_1=YOUR_SECRET
    client=radius_client
    failmode=safe
    
    • The proxy itself doesn’t enforce short timeouts-the ASA does. Extending ASA’s timeout is the critical step.

    Best Practices

    Set ASA RADIUS timeout to 60 seconds - aligns with Duo’s push window.

    Limit retries to 1–2 -avoids multiple overlapping pushes.

    Monitor logs - confirm Duo proxy receives requests and users approve within the timeout.

    Educate users - encourage quick Duo Push responses to avoid hitting the timeout.

    Fallback methods - allow passcodes or phone callbacks for users without push access.

    Risks & Trade‑offs

    Longer timeouts mean VPN sessions wait longer before failing, which can slightly delay rejection of invalid logins.

    Reducing retries lowers duplicate push notifications but may reduce resilience if a packet is dropped.

    Balance timeout and retries based on your network latency and user response behavior.

    In Summary: On Cisco ASA VPN with Duo MFA, set the RADIUS timeout to 30–60 seconds and reduce retries to 1–2. This gives users enough time to approve Duo Push while preventing rapid re‑prompts. Configure these values in the ASA aaa-server settings; Duo Authentication Proxy will honor them.

    Here are the most relevant Microsoft documentation links:

    Configure RADIUS Clients Shows how to set timeout and retry values for RADIUS clients in NPS. This illustrates the supported Microsoft approach to extending the authentication window for MFA responses. Microsoft Learn – Configure RADIUS Clients (learn.microsoft.com in Bing)

    Integrate Duo MFA with Microsoft NPS Duo’s official integration guide references Microsoft NPS and explains how RADIUS timeout values affect MFA push response times.

    Duo + Microsoft NPS Integration Guide

    I hope this helps to better understand the diagnostic options available and the risks involved.

    If this information was helpful, please click Accept Answer.

    Thank you for choosing Microsoft Q&A.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.