Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
martyyy
New Contributor III

Require Message-Authenticator from NAD

Hi,


Due to recent vulnerabilities in radius, we would like to enable Message-Authenticator on our clearpass server.
After enabling this option in clearpass, we get errors in clearpass that the radius packet received from FortiGate-1100E (v7.2.8 build1639 (Mature) is without Message-Authenticator as below.

Is it possible to enable this?

 

Source RADIUS
Level ERROR
Category Authentication
Action Unknown
Description
Failed to decode RADIUS packet - Received packet from x.x.x.x without Message-Authenticator

TIA :) 

1 Solution
rbraha
Staff
Staff

Hi @martyyy 

 

You will need to upgrade FTG to version 7.2.10 ,please check the release notes below.

 

https://docs.fortinet.com/document/fortigate/7.2.10/fortios-release-notes/5880/radius-vulnerability

View solution in original post

1 REPLY 1
rbraha
Staff
Staff

Hi @martyyy 

 

You will need to upgrade FTG to version 7.2.10 ,please check the release notes below.

 

https://docs.fortinet.com/document/fortigate/7.2.10/fortios-release-notes/5880/radius-vulnerability

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors