Fortigate RADIUS with Microsoft NAS
Hi,
I’m having a lot of trouble getting ourFortiGate firewalls (100Fs / v7.2.10 build1706) to connect to our Microsoft NAS RADIUS server (Windows Server 2022).
In NAS there is a tick box that says “Access-Request messages must contain the Message-Authenticator attribute”, my research shows that given version of the Forti software we are running, this should be ticked, however with this ticked Forti reports “Unable to reach RADIUS server” and Windows Event Viewer shows:
“An Access-Request message was received from RADIUS client 10.10.100.1 without a Message-Authenticator attribute when a Message-Authenticator attribute is required. Verify the configuration of the RADIUS client in the Network Policy Server snap-in (the "Client must always send the Message-Authenticator attribute in the request" checkbox) and the configuration of the network access server.”
If I untick it then Forti reports invalid secret (even though it’s been triple checked, reset, and checked some more) and event viewer shows
“An Access-Request message was received from RADIUS client 10.10.100.1 with a Message-Authenticator attribute that is not valid.”
If my own laptop as a client in NAS an use something like radlogin, it communicated with server ok so it seems to be an issue specific to Forti.
Thanks
