Skip to main content
SAJUDIYA
Staff
Staff
March 12, 2025

Troubleshooting Tip: 'The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.' error for RADIUS server logs when client failed to connect to Wi-Fi SSID

  • March 12, 2025
  • 0 replies
  • 2038 views
Description

This article describes an issue with the RADIUS server EAP type that cannot be processed by the server when the user connects to the Wi-Fi SSID. While checking RADIUS server logs, the following logs were observed for the user:

 

Error logs from Windows:

RADIUS Client:
Client Friendly Name: test
Client IP Address: 10.x.x.x 

Authentication Details:
Connection Request Policy Name: Use Windows authentication for all users
Network Policy Name: Wireless
Authentication Provider: Windows
Authentication Server: xxx.domain.com
Authentication Type: EAP
EAP Type: -
Account Session Identifier: 36363643393238373030314536323245
Logging Results: Accounting information was written to the local log file.
Reason Code: 22
Reason: The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server.

Scope All versions of FortiOS.
Solution
  1. Make sure that the following settings matched under certificate Authority(local) where RADIUS server is configured:

certificate settings.png

 

  1. Make sure that the certificate is valid. If not, renew it on the NPS server.
  1. If the same issue persists, it is possible a local certificate stored on the server hard drive is corrupted. It is therefore necessary to create a new NPS server, which should resolve the issue.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!