USG Flex 500H Passive device HA mode MFA error





Hello,
We have enabled MFA for the admin user.
When the Passive device becomes active we cannot access the gui because the MFA is not working.
When the Primary device returns active, we can access the gui normally.
Tried with firmware 1.32 ga and 132ABZH0ITS-0423-250300903
Thank you
Accepted Solution
-
I can't reproduce this behavoir in my lab, I wonder if the sync is not completed for 2fa google auth config
Please try this step- remove and re-create the admin account again, then enable 2FA for this admin account.
- input CLI to active firewall: cmd device-ha force-sync 2fa-google-auth
If still no work, please collect the information of this CLI: show state vrf main device-ha _debug sync-info
0
All Replies
-
@Zyxel_James any updates on this issue?
0 -
@Zyxel_Melen @Zyxel_Judy Please help us😉
0 -
I can't reproduce this behavoir in my lab, I wonder if the sync is not completed for 2fa google auth config
Please try this step- remove and re-create the admin account again, then enable 2FA for this admin account.
- input CLI to active firewall: cmd device-ha force-sync 2fa-google-auth
If still no work, please collect the information of this CLI: show state vrf main device-ha _debug sync-info
0 -
Hello @Zyxel_James I can confirm that your workaround solved the problem.
Just a note: since it's not possible to remove the built-in admin account, so I just revoked the 2FA codes for that account, recreated it and finally I ran the cli input as you wrote.
1
Categories
- All Categories
- 434 Beta Program
- 2.7K Nebula
- 172 Nebula Ideas
- 117 Nebula Status and Incidents
- 6.1K Security
- 405 USG FLEX H Series
- 296 Security Ideas
- 1.6K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 43 Wireless Ideas
- 6.7K Consumer Product
- 268 Service & License
- 412 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 83 Security Highlight