Created on 03-31-2024 11:21 PM Edited on 03-31-2024 11:23 PM By Anthony_E
Description | This article describes how to troubleshoot when hosts are getting Radius-Reject and the file radius.log contains the error 'ssl3_get_client_hello:no shared cipher'. |
Scope | FortiNAC, FortiNAC-F. |
Solution | This issue is because the host is not offering a cipher on the allowed list in the FortiNAC Radius TLS Configuration. If supplicant configuration is unable to be retrieved from the connecting host a packet capture can provide the necessary details. Commands and examples of how and what to capture can be found here.
Compare the list from the PCAP to the available ciphers found in the Local Radius config on the FortiNAC GUI:
The HOST and the Local Radius server will now have a common cipher. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.