We're having Fortigate 1000F in AP HA cluster.
We're having an IPSEC tunnel with remote location where we have Wireless access points. Those access points are authorizing clients via NACVIEW radius server which is located on our side of IPSEC tunnel.
Everything was working fine until we've upgraded our fortigates from 7.2.10 firmware to 7.4.7.
After the upgrade all RADIUS traffic via IPSEC tunnel stoppped. No traffic is seen on policicies in traffic log. Log is set up to ALL and before the upgrade we've had all the traffic logged. And of course RADIUS authorization stopped working. No request are arriving to NACVIEW radius server from the AP controller on other side of IPSEC tunnel.
After downgrading back to 7.2.10 everything started to work again.
Is there any bug in 7.4.x firmware reguarding the radius traffic over IPSEC tunnel that anyone know of?
We would like to upgrade to 7.4.x firmware due to new policy layout which is much more usefull than the old one.
hi,
maybe, bug id 869978 .
normal traffic through the ipsec tunnel was reaching the remote site?
Yes normal traffic worked without and trouble. I personally have 40f at home with ipsec tunnel to work and it worked without and trouble. Other traffic through other ipsec tunnel also worked without and trouble. Even other types traffic worked through the same tunnel where udp radius didn't. Maybe it's problem with udp traffic?
maybe it was a radius problem overall and not for wifi specifically ?
Yes I suspect it's a problem either with Radius traffic or entire UDP traffic because radius works on 1812 udp port. I can't confirm it because we downgraded back to 7.2.10 as soon as we identified the problem because a lot of our medical equipment is connected to that WiFi network and authorised by radius server on our side of the tunnel.
As for now we're closing the topic. Due to fact we were able to connect the remote site via a dedicated L2 Vlan the problem doesn't concern us anymore. After switching from IPSEC tunnel to normal L2 routing the problem doesn't exist anymore.
User | Count |
---|---|
2559 | |
1357 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.