Skip to main content
rudolf76
New Member
March 13, 2024
Question

Radius Authentication

  • March 13, 2024
  • 3 replies
  • 7064 views

Hello,

I know that this topic was already discussed in the forum, but the solution did not solved my issue. I have a problem with the RADIUS authentication from a FG100F to a NPS Windows Server. When I try to authenticate I get this error:

"AVP: l=22 t=Vendor-Specific(26) v=Microsoft(311) VSA: l=16 t=MS-CHAP-Error(2) Value: '<00>E=691 R=0 V=3'"

But I don't know if this error comes from the FG or from the NPS server.

 

The thing is, I have already a FG which is connected to the same RADIUS server and with this firewall it works. But when I connect another FG to the same RADIUS, it doesn't. 

So I guess the new firewall must be allowed somewhere in the NPS to make authentication requests.

Had someone other this problem as well, and maybe a solution?

Thank you!!!!!!

br

Rudolf

3 replies

ebilcari
Staff
Staff
March 13, 2024

In the RADIUS server you have to add the RADIUS clients (NAS), in this case the IP of the FGT. Pay attention to the source IP that FGT uses for these requests, if it's a different source IP (or NATed) the requests will be dropped. You can also specify the source IP when you configure the RADIUS server in FGT as  the NAS IP.

Emirjon
adimailig
Staff & Editor
Staff & Editor
March 14, 2024

Please refer to below guide on how to deploy Microsoft NPS (RADIUS). Please check if steps 1 - 5 is configured properly.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-FortiGate-and-Microsoft-NPS-Radius/ta-p/213024

You may also refer to below guide on how to troubleshoot, RADIUS authentication from Fortigate
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Radius-authentication-troubleshooting/ta-p/196192


rudolf76
rudolf76Author
New Member
March 20, 2024

Hi all, I'm a little bit closer to the solution. :)

It is possible to authenticate now against the Radius server. I get also a phone call from Microsoft because of MFA. This works so far. But after or during the authentication process I get this error when I try to authenticate via CLI on the FG:

 

authenticate 'user@domain.com' against 'mschap2' failed(no response), assigned_rad_session_id=1373936999 session_timeout=0 secs idle_timeout=0 secs!

 

And in the Fortigate GUI there is the message in the Radius config: Can't contact Radius server. After the auth. process has been finished, FG is able to connect the Radius server again.

 

So authentication works, but it immediately closes the connection.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!