> Source: [sk119597](https://support.checkpoint.com/results/sk/sk119597)

# sk119597 - "Radius not responding" error when MS-CHAP V2  encryption is used

| Property | Value |
|----------|-------|
| Solution ID | sk119597 |
| Date Created | 2017-08-23 |
| Last Modified | 2019-10-11 |
| Technical Level | Advanced |
| Products | Security Gateway, SmartConsole, Endpoint Security |
| Versions | R82.10, R82, R81.20, R82.10, Cloud, R82.20, R82, R81.20, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Radius Authentication fails with reason "Radius not responding", but there is full connectivity between the Gateway and the Radius Server.
* Under Radius Server properties, MS-CHAP v2 is selected in the protocol section.
* When changing the protocol type to PAP, the authentication is successful.
* In VPND.elg the following entries are found:  
  `
  [PID][DATE TIME][AU] RADIUS_login_info_create(RADIUS_login_info=aee7690): info created`  
  `
  [PID][DATE TIME][AU] CheckAuthenticatorResponse(rp=bfe3f88): MS-CHAP-SUCC2 calculated auth string = S=41E4F415BB799B34D85F1E849A759AD5EAE10121.`  
  `
  [PID][DATE TIME][AU] act_on_response(rp=bef6f88): packet integrity (MS-CHAP-SUCC2) failed`
* The MD5 calculation done by the Security Gateway is identical.  
  for example:  
  `[PID][DATE TIME][AU] check_respond_auth: Calculated md5:
  000: f3 5a 69 7e ba 75 fe 5c b2 a7 20 29 5c c1 7c 7b .Zi..u.\.. )\...`  
  `
  [PID][DATE TIME][AU] check_respond_auth: Received md5:
  000: f3 5a 69 7e ba 75 fe 5c b2 a7 20 29 5c c1 7c 7b .Zi..u.\.. )\...`
* Unable to log into Smart Console via a user setup to authenticate against a RADIUS server" and getting an Error " Authentication to server failed"

## Cause

The Radius server doesn't send the MS-CHAP2-SUCCESS Radius attribute at all or it is sent incorrectly.

According to RFC 2548 :

**"**2.3.3. MS-CHAP2-Success. This Attribute contains a 42-octet authenticator response string.

This string MUST be included in the Message field of the MS-CHAP- V2 Success packet sent from the NAS to the peer.

This Attribute is only used in Access-Accept packets."

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
