Technical Tip: RADIUS authentication non-functional after HA failover
Description
This article describes a known issue on FortiAuthenticator where RADIUS authentication would not be able to authenticate the user after an HA failover.
Scope
FortiAuthenticator.
Solution
The issue would occur when a new secondary FortiAuthenticator joins as a cluster member. Once cluster forming is completed and synchronization is fully synced successfully, performing a failover test at this stage will trigger the issue to occur; RADIUS authentication will fail.
The issue has been identified as a bug, scheduled to be fixed in the upcoming firmware release. Upgrading the existing FortiAuthenticator version will not trigger this condition.
After the new secondary successfully joins the cluster and the database sync, perform a reboot on the new secondary FortiAuthenticator, and it will resolve the issue. Even with subsequent failover testing, RADIUS authentication will be successful.
