Hi guys,
Newly, I’ve discovered that I can show Radius Reject Reply-Message on the cisco anyconnect authentication window by enabling this option:

but for some reason it’s not working, still showing the common message:

In debug log I can see that message, that I would like to get in anyconnect window:

In case if someone achieves this, please share info.
Thanks!
Interesting.
According to the RFC Accress-Reject packet is supposed to contain the error message in the attribte Reply-Message. The privacyIDEA RADIUS plugin does this.
I have not heart of any Reject-Message, yet. The message in either an Access-Accept, Access-Challenge or Access-Reject packet is supposed to be in Reply-Message.
It works on newer firmware versions such us: 5.6(1) ASA 5506 and 9.12(4) ASA 5515

Thanks!
1 Like