Skip to main content
DaveG-PW
Visitor III
January 27, 2025
Question

Fortigate RADIUS with Microsoft NAS

  • January 27, 2025
  • 8 replies
  • 5062 views

Hi,

 

I’m having a lot of trouble getting ourFortiGate firewalls (100Fs /  v7.2.10 build1706) to connect to our Microsoft NAS RADIUS server (Windows Server 2022).

 

In NAS there is a tick box that says “Access-Request messages must contain the Message-Authenticator attribute”, my research shows that given version of the Forti software we are running, this should be ticked, however with this ticked Forti reports “Unable to reach RADIUS server” and Windows Event Viewer shows:

 

An Access-Request message was received from RADIUS client 10.10.100.1 without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.

 

If I untick it then Forti reports invalid secret (even though it’s been triple checked, reset, and checked some more) and event viewer shows

 

An Access-Request message was received from RADIUS client 10.10.100.1 with a Message-Authenticator attribute that is not valid.

 

If my own laptop as a client in NAS an use something like radlogin, it communicated with server ok so it seems to be an issue specific to Forti.

 

Thanks

8 replies

AEK
SuperUser
SuperUser
January 27, 2025

Hi Dave

Are you hitting this known issue?

1075627

On the User & Authentication > RADIUS Servers page, the Test Connectivity and Test User Credentials buttons may incorrectly return a Can't contact RADIUS server error message when testing against a RADIUS server that requires the message-authentication attribute in the access request from the FortiGate.

This is a GUI display issue as the actual RADIUS connection does send the message-authentication attribute.

Workaround: confirm if the connection to RADIUS server using the CLI:

diagnose test authserver radius <server> <method> <user> <password>

AEK
DaveG-PW
DaveG-PWAuthor
Visitor III
January 27, 2025

Doesn't appear so, if I try the command then I get the following:

 

authenticate 'myusername' against 'chap' failed(no response), assigned_rad_session_id=450523000 session_timeout=0 secs idle_timeout=0 secs!

 

And nothing shows up in event viewer, I've tried with all 4 auth methods.

AEK
SuperUser
SuperUser
January 27, 2025

Are you sure the method is chap? Can you try others?

AEK
ebilcari
Staff
Staff
January 27, 2025

You can read more about this behavior (Blast RADIUS) in this article. 

A packet capture for RADIUS communication between FGT and NPS will tell if the new required attribute is present on sent/received packets.

Some details are also shown in the FGT GUI:

rad-test.PNG

Emirjon
DaveG-PW
DaveG-PWAuthor
Visitor III
January 27, 2025

I've taken a look at that article and ran the command to turn on debugging.

However I don't see that "Server message" section in the GUI when testing?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!