Bug: RADIUS Authentication Failing with Ivanti ICS 22.7R2.6

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: RADIUS
    Bug Number: Not provided in source
    Bug Status: Closed - Fixed
    Fixed in Version(s): SecureAuth RADIUS Server 24.07.05+

     

    Overview

    After upgrading Ivanti Connect Secure (ICS) to 22.7R2.6, RADIUS authentication through SecureAuth fails, even though the RADIUS logs show an Access-Accept response.

     

    Cause

    Ivanti ICS 22.7R2.6 introduced a hardcoded requirement for the Message-Authenticator attribute to be present in the RADIUS response. Some versions of SecureAuth RADIUS do not include the Message-Authenticator attribute in their response packet — even with the Message-Authenticator checkbox selected in SecureAuth RADIUS 24.07.03 — so Ivanti silently drops the response and authentication fails for the end user.

     

    Resolution / Workaround

    Upgrade SecureAuth RADIUS to 24.07.05 or later, which sends the Message-Authenticator attribute correctly. See the SecureAuth RADIUS Server release notes for details, and the Product Downloads page to get the update.

     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.