Skip to main content
tanr
New Member
December 16, 2016
Solved

FortiAnalyzer with 5.4.2 firmware fails RADIUS authentication against FortiAuthenticator

  • December 16, 2016
  • 9 replies
  • 12351 views

I decided to roll the dice and upgrade a FortiAnalyzer 200D to the new 5.4.2 firmware.

I followed the upgrade guide and rebooted before the upgrade, etc.

 

Everything seemed fine till I noticed that all authentication against RADIUS on the FortiAuthenticator 200D 4.1.2 was failing.  I mostly use this to give me two-factor authentication with FortiTokens for admins on the FAZ.

 

Checking further, everything seemed to be going through, but the FAC always reported "Invalid Password".  Note that my FortiGate is still working with the FAC without problem.

 

I tried a number of things, all without success:

[ul]
  • Re-entering the RADIUS secret for the FAZ and the FAC
  • Completely recreating the FAC's RADIUS client and the FAZ's Remote Auth (RADIUS) server
  • Removing and recreating local users on the FAC, removing and recreating the RADIUS users on the FAZ
  • Updating the FAC to the most recent firmware (4.2.0)
  • Trying users without two-factor authentication
  • Trying different EAP methods
  • Verify the nas-ip was properly set for the FAZ (it was)
  • Trying RADIUS users (on the FAZ) with wildcard, without wildcard, without the password set, with the password set, etc.
  • Changing the way the FAC realm (which just refers to local anyway) was referred to from the FAZ[/ul]

    So, I'm stumped, and it's looking like time for Wireshark.  It appears that the password just isn't being correctly sent from the FAZ to the FAC's RADIUS server.

     

    Any suggestions?  Besides "Never be the first one to upgrade the firmware" that is...

     

    Thanks.

    • Best answer by mel

      We had the same issue - we had to change the radius key to a 16 character key - 17 characters and above doesn't seem to work anymore

      9 replies

      emnoc
      New Member
      December 16, 2016

      Here's what I would do

       

      1: run a radiusdump or radiussniff utility  on capture radius flow while authentication

      2: it seems like you did re-keyed the radius secrete but  re-keyed a temporal simple key  on both units ( server/client ) for testing. I'm assuming when you rebuilt it you might have done just that

      3: are you using chap/pap/MSchap/etc...( above radius dump/sniff will display that )

      4: what does the logs show at the radisuclient and server

      5: does 5.4.2 have any new  "diag test application" solution for authorization ( check )

       

      Ken

       

      hzhao_FTNT
      Staff
      Staff
      December 16, 2016

      Hi there, QA is unable to reproduce your issue in lab.  I would suggest you open a ticket for this issue and post the ticket number in forum.

       

      Regards,

      hz

      tanr
      tanrAuthor
      New Member
      December 16, 2016

      @hzhao_FTNT, thanks for looking into this.  I'll open a support ticket later today.

       

      @emnoc,

       

      Thanks for the suggestions.  

       

      1. I'm not familiar with any specific radius dump or sniffer utility.  Any you would suggest?

          Also, any simple radius client I might use to test this scenario?

       

      2. I already tried a different simple key for both client and server, as well as rebuilding.  I haven't tried doing it with a different IP yet, in case this is related to something being cached.  I did already clear the client machine's cache, but I don't know if there is something else needed for the FAZ.

       

      3. I've tried most of the EAP combinations, which give various errors related to EAP before even getting to checking the password.  PAP from the FAZ seems to work the best, except for the invalid password of course. 

       

      4. The logs are pretty brief.  I've included the only items I got, with a test user account on the FAC.  Names and IPs below have been XX'd, but were all correct (so, for instance, the FAC's nas IP matched the NAS IP it was expecting).  I have not yet tried to set the FAC or FAZ to be more verbose.

      FAC log shows only:

      status=Failed nas=IP.IP.IP.IP itime=2016-12-15 19:54:12 vd=root level=information devid=FAC-XXXXXXX dtime=2016-12-16 03:54:12 logid=20102 subtype=Authentication devname=FAC-XXXX itime_t=1481860452 user=testmgr@XXXX.XXX logdesc=AUTH_FAIL_BADPASS time=03:54:12 date=2016-12-16 type=event action=Authentication msg=Local administrator authentication with no token failed: invalid password

       

      FAZ event log shows only:

      016-12-15 19:54:13 log_id=0001010019 type=event subtype=system pri=alert user="testmgr@XXX.XXX" userfrom="GUI(IP.IP.IP.IP)" msg="User 'testmgr@XXXXX.XXX' login failed from GUI(IP.IP.IP.IP), reason:Authentication failure. Please try again..." adminprof=""

       

      5.  FAZ has diag test app but no apps that look associated with RADIUS.  Maybe diag debug service, if I could find a description of the services.  Since I'm not too familiar with CLI on the FAX I'll probably need to go through it with support.

       

      mel
      melAnswer
      New Member
      February 21, 2017

      We had the same issue - we had to change the radius key to a 16 character key - 17 characters and above doesn't seem to work anymore

      tanr
      tanrAuthor
      New Member
      February 21, 2017

      Thanks for the info, I'll try shortening the keys and post how it goes.

       

      Did you report this as a bug to Fortinet?

      tanr
      tanrAuthor
      New Member
      February 22, 2017

      With FAC 4.2.1, trying with a 16 character radius key still gives the same failure messages as listed above when attempting to use MSv2 (mschap) or CHAP for RADIUS authentication from FAZ 5.4.2.  I can only make it work with PAP.

       

      Now that I'm back on site I've opened a support ticket, and will post the results here.

       

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!