Radius server cannot be connected to because it requires authentication message
Confirmed 7/20/2026
Problem
Radius server cannot be connected to because it requires authentication message
Symptoms
rejecting RADIUS responses with an unrecognized proxy state attribute
Environment
FortiGate
FortiOS version
All Versions
Root Cause
This is occurring because FortiGate have applied mitigations to protect against the Blast RADIUS vulnerability. These mitigations include enforcing the validation of the Message-Authenticator RADIUS attribute (i.e., dropping server connections that fail to provide the attribute) and rejecting RADIUS responses with an unrecognized proxy state attribute. However, RADIUS servers may not have been updated to support these same mitigations, and in those cases, RADIUS authentication will not be successful
Solution
Recommended is that RADIUS servers must be updated to enable the Message-Authenticator attribute and include it in RADIUS messages. If the Radius Server is not updated to support this function, the require-message-authenticator must be disabled on the FortiGate: config user radius edit "<server>" set require-message-authenticator disable next end
Tags
No tags yet.
Community rating
— / 5 (0)