sk183244 - RADIUS authentication fails after installing Jumbo Hotfix Accumulator
RADIUS authentication fails after installing Jumbo Hotfix Accumulator
Product
Identity Awareness, Mobile Access / SSL VPN, Multi-Domain Security Management, Remote Access VPN, Security Gateways, Security Management
Version
R81.10 (EOS), R81.10.X, R81.20, R82, R82.10
OS
Gaia, Gaia Embedded
Last Modified
2025-09-29
Symptoms
- The RADIUS server is adding the Message-Authenticator attribute value pair (type 80) to response packets.
- Packet captures show that the Message-Authenticator attribute value pair is not the first attribute value pair contained in the response packet.
The following example shows a RADIUS payload from a response packet meeting these criteria (the Message-Authenticator attribute value pair is the third attribute value pair contained in the payload):
RADIUS Protocol
Code: Access-Accept (2)
Packet identifier: 0xXX
Length: 85
Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
[This is a response to a request in frame 1]
[Time from request: 0.083880000 seconds]
Attribute Value Pairs
AVP: t=Vendor-Specific(26) l=35 vnd=Open System Consultants(9048)
Type: 26
Length: 35
Vendor ID: Open System Consultants (9048)
VSA: t=Unknown-Attribute(18) l=29 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Type: 18
Length: 29
Unknown-Attribute: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
AVP: t=Vendor-Specific(26) l=12 vnd=Check Point Software Technologies Ltd(2620)
Type: 26
Length: 12
Vendor ID: Check Point Software Technologies Ltd (2620)
VSA: t=Unknown-Attribute(230) l=6 val=00000001
Type: 230
Length: 6
Unknown-Attribute: 00000001
AVP: t=Message-Authenticator(80) l=18 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Type: 80
Length: 18
Message-Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Debugs for the relevant daemon show the following errors:
check_respond_msg_auth: Comparison result: 1
act_on_response(rp=xxxxxx): Message-Authenticator integrity failed, also happened x times before
Cause
The hotfix that addresses Check Point's Response to CVE-2024-3596 - Blast-RADIUS attack expects the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets when present.
This decision was based on the verbiage contained in the RFC draft Deprecating Insecure Practices in RADIUS published by the IETF.
However, RFC3579 "RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)" does not define a strict requirement for the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets.
Solution
For Gaia appliances:
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 36
- Jumbo Hotfix Accumulator for R81.20 starting from Take 111
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
For Gaia Embedded appliances:
Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-03-13
Last Modified: 2025-09-29