MFA solution and Mikrotik

Hi!

Ive got some troubles to integrate MFA solution to RouterOS login (admin access). At first: Client Idenity: MFA service give to me 3 parameters: Client ID, Password, Name of radius server. I cant setup Client ID (NAS Identifier) from radius setting. Only change router name can help me…
I can`t use FDQN for radius server, only by IP. Why not FDQN!?

Ok, I change router name to “dlkfgnsdfghisrhtoisrnthoguifrnsoignosf”, use nslookup for search ip and…
Now I can’t login to winbox, becouse it use PAP and PAP is unsecure.

I never give up! I will use only second factor! And…

I can to login over SSH and I can login over WEB…
But I can’t login over Winbox. :open_mouth:

Winbox say to me error: Wrong username or password

Radius server send “accept”, I have in log: logged in and immediately logged out.

May be I do something wrong!?
Pls help me…
RadiusReply.png
Wrong.png

Lastest Winbox 3.37 and RouterOS 7.8 move from PAP to MSCHAP.
You can use NPS with normal (not reversible encription) password.

Have a good day!