About the Okta RADIUS Agent and Applications

The Okta RADIUS Server agent:

  • Is a lightweight program that runs as a system service.
  • Tunnels communication between on-premises services and Okta's cloud service.
  • Delegates authentication to Okta using single-factor authentication (SFA) or multi-factor authentication (MFA).
  • Supports the Password Authentication Protocol (PAP).
  • Supports EAP Generic Token Card (EAP-GTC).
    Currently only supported by NetMotion mobility.
  • Supports EAP Tunneled Transport Layer Security (EAP-TTLS) with PAP as the inner authentication protocol within the secure TLS tunnel.
    Currently the Cisco Meraki and Cisco ASA RADIUS apps support configuration for EAP-TTLS.
  • Supports UDP, defaulting to port 1812, using multiple ports simultaneously.