USG Flex 500H Passive device HA mode MFA error

Mk88_it
Mk88_it Posts: 67  Ally Member
First Comment Friend Collector Third Anniversary
edited May 21 in USG FLEX H Series

Hello,

We have enabled MFA for the admin user.

When the Passive device becomes active we cannot access the gui because the MFA is not working.

image.png

When the Primary device returns active, we can access the gui normally.

Tried with firmware 1.32 ga and 132ABZH0ITS-0423-250300903

Thank you

Accepted Solution

  • Zyxel_James
    Zyxel_James Posts: 759  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers
    Answer ✓

    @Mk88_it

    I can't reproduce this behavoir in my lab, I wonder if the sync is not completed for 2fa google auth config
    Please try this step

    1. remove and re-create the admin account again, then enable 2FA for this admin account.
    2. input CLI to active firewall: cmd device-ha force-sync 2fa-google-auth

    If still no work, please collect the information of this CLI: show state vrf main device-ha _debug sync-info

All Replies

  • Dylan96
    Dylan96 Posts: 31  Freshman Member
    Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security First Comment Friend Collector

    @Zyxel_James any updates on this issue?

  • Mk88_it
    Mk88_it Posts: 67  Ally Member
    First Comment Friend Collector Third Anniversary

    @Zyxel_Melen @Zyxel_Judy Please help us😉

  • Zyxel_James
    Zyxel_James Posts: 759  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers
    Answer ✓

    @Mk88_it

    I can't reproduce this behavoir in my lab, I wonder if the sync is not completed for 2fa google auth config
    Please try this step

    1. remove and re-create the admin account again, then enable 2FA for this admin account.
    2. input CLI to active firewall: cmd device-ha force-sync 2fa-google-auth

    If still no work, please collect the information of this CLI: show state vrf main device-ha _debug sync-info

  • Mk88_it
    Mk88_it Posts: 67  Ally Member
    First Comment Friend Collector Third Anniversary

    Hello @Zyxel_James I can confirm that your workaround solved the problem.

    Just a note: since it's not possible to remove the built-in admin account, so I just revoked the 2FA codes for that account, recreated it and finally I ran the cli input as you wrote.