How To: Test RADIUS Using RadTest

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to use RadTest, a Windows utility, to send test RADIUS authentication requests to a SecureAuth RADIUS Server, including testing a second-factor challenge/response.

     

    Test RADIUS Using RadTest

    1. In RadTest, right-click in the task list and select New Task.

    RadTest task list with a right-click context menu open, showing New Task highlighted at the top.

    1. On the General Options tab, enter the RADIUS server's hostname or IP address, the shared secret, the RADIUS packet type (Access-Request), the authentication method (for example, PAP), and the RADIUS port (1812 by default).

    Task Properties dialog's General Options tab, showing fields for the RADIUS server's hostname or IP address, shared secret, packet type, authentication method, and port number.

    1. On the Additional Packets tab, add a new packet with the attributes user-name and user-password set to the test account's username and password.

    Task Properties dialog's Additional Packets tab, adding a new packet with the user-name and user-password attributes filled in.

    1. Run the task. If the realm requires a second factor, the response is an Access-Challenge rather than an immediate Access-Accept. The Reply-Message shows what the RADIUS server is requesting next (for example, a time-based passcode, or a choice of SMS, phone, or email delivery) — note the returned State attribute, since it must be reused in the next request to continue this same authentication attempt.

    RadTest log showing an Access-Challenge response, with the Reply-Message prompting for a time-based passcode or a choice of SMS, phone, or email delivery, and the State attribute to copy for the next request.

    1. Edit the same task again and return to the Additional Packets tab — modify the existing packet rather than adding a new one. Remove the original user-password value and replace it with the second-factor response (for example, an OTP), and add a state attribute set to the value copied in the previous step.

    Task Properties dialog's Additional Packets tab, with the user-password value replaced by an OTP and a state attribute added with the copied challenge state value.

    1. Run the task again. A Reply-Message of Access granted confirms the second factor was accepted.

    RadTest log showing a successful authentication, with the Reply-Message field reading Access granted and Total approved auths showing 1.

     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.