Skip to main content
cmaheu
Staff
Staff
December 12, 2024

Troubleshooting Tip: Require Message-Authentication set to 'Enable' causes RADIUS health check failure

  • December 12, 2024
  • 0 replies
  • 2084 views
Description

This article describes the behavior where in High Availability configurations, the RADIUS health check fails when the RADIUS service is running properly. It can be triggered when the Require Message-Authenticator attribute is set to 'enable' under Network -> RADIUS -> Configuration in the FortiNAC Admin GUI.  When the health check fails, FortiNAC initiates a failover to the secondary.


'Require Message-Authenticator' Option Descriptions:

  • Enabled: Require Message-Authenticator attribute for all Access-Request, Access-Accept, and Access-Reject messages to enable BlastRADIUS protection.
  • Disabled: BlastRADIUS protection is disabled.
  • Auto: Enables BlastRADIUS protection for NAS clients that send the Message-Authenticator attribute while still supporting legacy NAS clients that do not. Note that BlastRADIUS protection will not be enabled for legacy NAS clients.


The authentication test packets sent by the health check do not contain the Message-Authenticator attribute and are dropped.

This leads FortiNAC's health check logic to think RADIUS is not responding and triggers a failover.

Scope FortiNAC vF7.2.8, vF7.4.0, vF7.6.0 and greater.
Solution

This will be addressed in a future release.

 

Workaround: FortiNAC GUI Method.
Go under Network -> RADIUS -> Configuration and set the Require Message-Authenticator option to either Auto or Disabled.


Workaround - FortiNAC CLI Method (FortiNAC-OS):

Disable the RADIUS component of the health check. Login as admin and type:


execute enter-shell
globaloptiontool -name highAvail.radiusCheckEnabled -set "false"
exit

 

Workaround - FortiNAC CLI Method (CentOS):

Disable the RADIUS component of the health check. Login as root and type:


globaloptiontool -name highAvail.radiusCheckEnabled -set "false"

logout

 

The secondary server is in control: once the settings are changed, resume control to the primary server. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!