> Source: [sk182100](https://support.checkpoint.com/results/sk/sk182100)

# sk182100 - Maestro Security Group shows the Sync IP when trying to authenticate to the RADIUS Server

| Property | Value |
|----------|-------|
| Solution ID | sk182100 |
| Date Created | 2024-03-14 |
| Last Modified | 2024-03-18 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * When trying to authenticate to the RADIUS Server, the Maestro Security Group shows the Sync IP.

* The Maestro Internal Sync IP has to be added to the RADIUS Server for authentication to work correctly, even though the packet is sourced from a non-sync interface.

## Cause

The payload lists the internal Sync IP as the NAS-IP:  

**172.25.47.30.33648 > 172.25.47.151.1812**`: [udp sum ok] RADIUS, length: 85`  
` Access-Request (1), id: 0xf9, Authenticator: d82ce8ffe7173a9dd9bdd41886120f2f`  
` User-Name Attribute (1), length: 9, Value: cpadmin`  
` 0x0000: 6370 6164 6d69 6e`  
` User-Password Attribute (2), length: 18, Value:`  
` 0x0000: 98ac ac7f 7000 d858 fa7b 25ca 4764 c0bc`  
` `**NAS-IP-Address Attribute (4), length: 6, Value: 192.0.2.1**  
` 0x0000: c000 0201`  
` NAS-Identifier Attribute (32), length: 6, Value: sshd`  
` 0x0000: 7373 6864`  
` NAS-Port Attribute (5), length: 6, Value: 12349`  
` 0x0000: 0000 303d`  
` NAS-Port-Type Attribute (61), length: 6, Value: Virtual`  
` 0x0000: 0000 0005`

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
