FortiNAC-F
FortiNAC-F is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks. For legacy FortiNAC articles prior to FortiNAC-F 7.2, see FortiNAC.
blarochelle
Staff
Staff
Article Id 349611
Description This article describes how to resolve FortiNAC dropping RADIUS RADSEC packets due to 'invalid Message-Authenticator! (The shared secret is incorrect.)' errors are seen in radius.log.
Scope FortiNAC-C, FortiNAC-F versions v7.2.1+, v7.4+,v 7.6+ and future versions.
Solution

Check 'radius.log' for an error message similar to the following:

 

'Dropping packet without response because of error: Received packet from 10.0.13.71 with invalid Message-Authenticator! (The shared secret is incorrect.) (from client 10.0.13.71)'.

 

RADSEC uses a fixed string for the shared secret - the fixed string is 'radsec'.

 

Add/modify the secret 'radsec' as the RADIUS secret in the model configuration of your network devices in Network -> Inventory.

 

 
ZGIYiVUnxC.png
 

Related document:

Model configuration