ASA RADIUS configuration

Hello Donald

In your post you mention that the freeRADIUS server has an IP address of 192.168.255.176/24 and that the ASA has an IP address of 192.168.8.5/24. Can you tell us a little more about your topology? Is the freeRadius server directly connected to an ASA interface, and if so, which one? If not, via what interface does it connect? Also, the IP address of the ASA, is that an INSIDE interface?

The reason I’m asking is that the ASA, by default, allows certain communications to take place while blocking others. The issue doesn’t seem to be related to RADIUS or to the ASA AAA config but to basic connectivity.

ALso, the fact that free radius can ping the ASA while the opposite is not possible also indicates that the issue is indeed connectivity. If a ping is possible in one direction it should be possible in the other. However, when pinging from the ASA, it may use a different source interface, resulting in different behavior.

Let us know these details about your topology so we can help you further with your troubleshooting.

I hope this has been helpful!

Laz