Description |
This article describes how to handle the 'Cannot decode the password' error on Cisco DUO RADIUS installed on a Windows Server and at the same time on the FortiGate the 'Invalid Password' error. |
Scope |
FortiGate. |
Solution |
The configuration of a RADIUS client is made on the FortiGate to send the user authentication to the Cisco DUO RADIUS proxy first both of them establish communication with each other.
After a sniffer capture (E.g. diagnose packet capture "host X.X.X.X" 6 0 l) when a communication test of authentication at RADIUS level from the FortiGate the next is shown:
0040 43 61 6e 6e 6f 74 2e 64 65 63 6f 64 65 2e 70 61 Cannot.d ecode.pa
If the configuration is created on the RADIUS template on the FortiGate at IP/name and Secret, the error shown on the 'connection status' is 'Invalid Password' and on the Cisco DUO RADIUS the error is 'Cannot decode the password' could be for two reasons:
If any change is made at Cisco DUO RADIUS, the proxy is needed to restart the process because could not reflect the change at the moment. |