> Source: [sk183244](https://support.checkpoint.com/results/sk/sk183244)

# sk183244 - RADIUS authentication fails after installing Jumbo Hotfix Accumulator

| Property | Value |
|----------|-------|
| Solution ID | sk183244 |
| Date Created | 2025-03-13 |
| Last Modified | 2025-09-29 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * The RADIUS server is adding the Message-Authenticator attribute value pair (type 80) to response packets.   

* Packet captures show that the Message-Authenticator attribute value pair is not the first attribute value pair contained in the response packet.   

  The following example shows a RADIUS payload from a response packet meeting these criteria (the Message-Authenticator attribute value pair is the third attribute value pair contained in the payload):
  >
  >     
  >     RADIUS Protocol
  >         Code: Access-Accept (2)
  >         Packet identifier: 0xXX
  >         Length: 85
  >         Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  >         [This is a response to a request in frame 1]
  >         [Time from request: 0.083880000 seconds]
  >         Attribute Value Pairs
  >             AVP: t=Vendor-Specific(26) l=35 vnd=Open System Consultants(9048)
  >                 Type: 26
  >                 Length: 35
  >                 Vendor ID: Open System Consultants (9048)
  >                 VSA: t=Unknown-Attribute(18) l=29 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  >                     Type: 18
  >                     Length: 29
  >                     Unknown-Attribute: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  >             AVP: t=Vendor-Specific(26) l=12 vnd=Check Point Software Technologies Ltd(2620)
  >                 Type: 26
  >                 Length: 12
  >                 Vendor ID: Check Point Software Technologies Ltd (2620)
  >                 VSA: t=Unknown-Attribute(230) l=6 val=00000001
  >                     Type: 230
  >                     Length: 6
  >                     Unknown-Attribute: 00000001
  >             AVP: t=Message-Authenticator(80) l=18 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
  >                 Type: 80
  >                 Length: 18
  >                 Message-Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

  <br />

  <br />

* Debugs for the relevant daemon show the following errors:  
  `check_respond_msg_auth: Comparison result: 1`   

  `act_on_response(rp=xxxxxx): Message-Authenticator integrity failed, also happened x times before`

## Cause

The hotfix that addresses [Check Point's Response to CVE-2024-3596 - Blast-RADIUS attack](https://support.checkpoint.com/results/sk/sk182516 "Check Point's Response to CVE-2024-3596 - Blast-RADIUS attack") expects the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets when present.  

This decision was based on the verbiage contained in the RFC draft [Deprecating Insecure Practices in RADIUS](https://www.ietf.org/archive/id/draft-ietf-radext-deprecating-radius-02.html "Deprecating Insecure Practices in RADIUS") published by the IETF.  

However, RFC3579 "RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)" does not define a strict requirement for the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets.

## Solution

**For Gaia appliances:**

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 36
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 111
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

**For Gaia Embedded appliances:**

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
