Skip to main content

Log File contains many Deny entries for Okta RADIUS agent's IP

Reviewing your Okta logs for a tenant, you observe many Deny entries for the IP address where the Okta RADIUS agent is installed.

Cause

Okta ThreatInsight blocks all connections where requests appear suspicious, and no network zone exemption has been configured for the IP address of the Okta RADIUS agent.

Resolution

Add the RADIUS agent's IP address as an exempt network zone for Okta ThreatInsight:

  1. Deep Link (recommended) or log in to the Okta Admin Console and navigate to Security > Networks.

  2. Click Add Zone > IP Zone.

  3. Provide a meaningful Name for the zone, such as "RADIUS Agent".

  4. Enter the IP address to allow and click Save.

  5. Navigate to Security > General, scroll down to Okta ThreatInsight settings, and click Edit.

  6. Under Exempt Zones, add the network zone you just created.

  7. Click Save.

Note that it can take up to 40 minutes for the IP to propagate in Okta, though it is typically updated much faster. For more information on managing blocked IPs in ThreatInsight, see How to Unblock an IP Address that is Blocked by ThreatInsight.


If the steps above do not resolve the issue, contact ZeroTek Support at [email protected].

Did this answer your question?