← Back to knowledge base
mediumAuthentication & FSSO

Radius server cannot be connected to because it requires authentication message

Confirmed 7/20/2026

Problem

Radius server cannot be connected to because it requires authentication message

Symptoms

rejecting RADIUS responses with an unrecognized proxy state attribute

Environment

FortiGate

FortiOS version

All Versions

Root Cause

This is occurring because FortiGate have applied mitigations to protect against the Blast RADIUS vulnerability. These mitigations include enforcing the validation of the Message-Authenticator RADIUS attribute (i.e., dropping server connections that fail to provide the attribute) and rejecting RADIUS responses with an unrecognized proxy state attribute.  However, RADIUS servers may not have been updated to support these same mitigations, and in those cases, RADIUS authentication will not be successful

Solution

Recommended is that RADIUS servers must be updated to enable the Message-Authenticator attribute and include it in RADIUS messages.  If the Radius Server is not updated to support this function, the require-message-authenticator must be disabled on the FortiGate:  config user radius      edit "<server>"          set require-message-authenticator disable      next  end

Tags

No tags yet.

Community rating

/ 5 (0)

Sign in to rate

Discussion (0)

    No comments yet.

Sign in to join the discussion.