Radius Attribute type 102 IPS Alerts (around 400K a week)
We have FGTs deployed and we dont have our FGTs configured for any RADIUS authentication service/server.
Whenever a user authentication traffic passes through the fortigate to our remote authentication RADIUS Server having attribute type of 102 in the payload (i.e EAP_KEY_NAME Attribute) - Fortigate flags it and raises it as an IPS Event. - Even though FGT is not even configured for any authentication services.
Can anyone help why is this happening? and how can i remedy this?
One way is to exempt the signature itself from getting flagged, but why is this happening in the first place and should we manually add the attribute ? - but we dont have any RADIUS Server configured or any user groups of RADIUS on our fortigate.
How can we remedy this ?