Hello @Syafiq Hamid
Welcome to Microsoft Q&A!
Thank you for your patience, and taking the time to elaborate on your concerns.
Yes, you can extend the RADIUS timeout and retransmit settings on Cisco VPN appliances to better accommodate Duo MFA push response times. The recommended approach is to increase the RADIUS server timeout and reduce the number of rapid retransmissions so users have enough time to approve Duo Push before the VPN session fails.
Key Cisco/Duo Settings.
On Cisco ASA/AnyConnect VPN (RADIUS integration):
RADIUS Server Timeout
Default: 5 seconds
Recommended with Duo: **30–60 seconds**
Command (ASA CLI):
bash
```sql
aaa-server DUO-RADIUS protocol radius
```aaa-server DUO-RADIUS (inside) host <DuoProxyIP>
timeout 60
```
```yaml
This ensures the ASA waits long enough for Duo Push approval.
**Retries**
Default: **3 retries**
Recommended: **1–2 retries**
Too many retries cause rapid re‑prompts and session failures.
Command:
bash
```sql
aaa-server DUO-RADIUS (inside) host <DuoProxyIP>
```retries 1
```
**On Duo Authentication Proxy (**`authproxy.cfg`**):**
Duo recommends matching the ASA timeout with the proxy’s `radius_server_auto` section.
Example:
ini
```yaml
[radius_server_auto]
ikey=YOUR_IKEY
skey=YOUR_SKEY
api_host=api-XXXXXXXX.duosecurity.com
radius_ip_1=ASA_IP
radius_secret_1=YOUR_SECRET
client=radius_client
failmode=safe
- The proxy itself doesn’t enforce short timeouts-the ASA does. Extending ASA’s timeout is the critical step.
Best Practices
Set ASA RADIUS timeout to 60 seconds - aligns with Duo’s push window.
Limit retries to 1–2 -avoids multiple overlapping pushes.
Monitor logs - confirm Duo proxy receives requests and users approve within the timeout.
Educate users - encourage quick Duo Push responses to avoid hitting the timeout.
Fallback methods - allow passcodes or phone callbacks for users without push access.
Risks & Trade‑offs
Longer timeouts mean VPN sessions wait longer before failing, which can slightly delay rejection of invalid logins.
Reducing retries lowers duplicate push notifications but may reduce resilience if a packet is dropped.
Balance timeout and retries based on your network latency and user response behavior.
In Summary: On Cisco ASA VPN with Duo MFA, set the RADIUS timeout to 30–60 seconds and reduce retries to 1–2. This gives users enough time to approve Duo Push while preventing rapid re‑prompts. Configure these values in the ASA aaa-server settings; Duo Authentication Proxy will honor them.
Here are the most relevant Microsoft documentation links:
- Network Policy Server (NPS) RADIUS Authentication Explains how RADIUS timeouts and retries work in Microsoft’s NPS role. While this is Windows‑based, the same concepts apply to Cisco ASA as a RADIUS client. Microsoft Learn – NPS RADIUS Authentication (learn.microsoft.com in Bing)
- https://duo.com/docs/ciscoasa-radius?utm_source=copilot.com
Configure RADIUS Clients Shows how to set timeout and retry values for RADIUS clients in NPS. This illustrates the supported Microsoft approach to extending the authentication window for MFA responses. Microsoft Learn – Configure RADIUS Clients (learn.microsoft.com in Bing)
Integrate Duo MFA with Microsoft NPS Duo’s official integration guide references Microsoft NPS and explains how RADIUS timeout values affect MFA push response times.
Duo + Microsoft NPS Integration Guide
I hope this helps to better understand the diagnostic options available and the risks involved.
If this information was helpful, please click Accept Answer.
Thank you for choosing Microsoft Q&A.