How To: Test RADIUS Using NTRadPing

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to use NTRadPing to test a RADIUS server configuration, including a second-factor (2FA) challenge/response.

    1. Download NTRadPing from the NTRadPing 1.5 RADIUS Test Utility page, then unzip it. NTRadPing is a standalone tool — copy NTRADPING.EXE and RADDICT.dat to a folder of your choice and run the .exe; no installation is required.
    2. Open NTRadPing and fill in the fields for your environment: RADIUS Server/port, RADIUS Secret key, and the test user's User-Name and Password. Leave CHAP unchecked — SecureAuth RADIUS only supports PAP. Click Send.
      NTRadPing with the RADIUS server, secret key, username, and password fields filled in, showing an Access-Challenge response with a State value and a Reply-Message asking for a time-based passcode.
    3. If the realm requires only a password, the response shows Access-Accept and testing is complete. If the realm also requires a second factor, the response instead shows Access-Challenge, with a Reply-Message asking for a passcode and a State value.
    4. To respond to the challenge: in Additional RADIUS Attributes, add a State attribute set to the State value from the previous response, and change Password to the OTP code from your SecureAuth authenticator. Click Send again.
      NTRadPing with a State attribute added to Additional RADIUS Attributes and the Password field changed to an OTP code, ready to send the second request.
    5. The response now shows Access-Accept, with a Reply-Message of Access granted.
      NTRadPing showing a response of Access-Accept with Reply-Message=Access granted.



     

    Special Considerations

    If NTRadPing shows repeated "no response from server (timed out)" messages instead of a reply, this is usually caused by a firewall blocking the request — confirm the RADIUS port is reachable between the NTRadPing client and the SecureAuth appliance.

    NTRadPing showing repeated no response from server (timed out) messages after sending a request.

    The OTP code must be typed in manually — NTRadPing does not support pasting it. Since the passcode is time-based, have it ready before sending the challenge response, or increase the reply timeout for testing.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.