> Source: [sk182960](https://support.checkpoint.com/results/sk/sk182960)

# sk182960 - RADIUS server denies user authentication

| Property | Value |
|----------|-------|
| Solution ID | sk182960 |
| Date Created | 2025-01-02 |
| Last Modified | 2025-01-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * RADIUS server denies user authentication even though Accept packets with the correct attribute are sent from the RADIUS server side, accepted on the MFA side, and received by the Security Gateway.

* The file */var/log/messages* contains these messages:  
  `
  ? Logging out from webui, user is not a TACACS user`  
  `
  ? Logging out from webui, user is not a RADIUS user
  `

  <br />

* The file */var/log/secure* contains these errors:  
  `
  ? pam_radius_auth: All RADIUS servers failed to respond.`  
  `
  ? RADIUS server ` fails verification: The shared secret is probably incorrect.  
  ? Failed password for from port.  

  <br />

* The issue persists if you verify or change the password.

## Cause

The default timeout on Gaia's PAM RADIUS module for AAA authentication is three seconds, which is too short for an environment with MFA configured on the server side.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
