# RADIUS authentication fails after installing Jumbo Hotfix Accumulator

## Product
Identity Awareness, Mobile Access / SSL VPN, Multi-Domain Security Management, Remote Access VPN, Security Gateways, Security Management

## Version
R81.10 (EOS), R81.10.X, R81.20, R82, R82.10

## OS
Gaia, Gaia Embedded

## Last Modified
2025-09-29

## Symptoms
- The RADIUS server is adding the Message-Authenticator attribute value pair (type 80) to response packets.
- Packet captures show that the Message-Authenticator attribute value pair is not the first attribute value pair contained in the response packet.

The following example shows a RADIUS payload from a response packet meeting these criteria (the Message-Authenticator attribute value pair is the third attribute value pair contained in the payload):

```
RADIUS Protocol
    Code: Access-Accept (2)
    Packet identifier: 0xXX
    Length: 85
    Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    [This is a response to a request in frame 1]
    [Time from request: 0.083880000 seconds]
    Attribute Value Pairs
        AVP: t=Vendor-Specific(26) l=35 vnd=Open System Consultants(9048)
            Type: 26
            Length: 35
            Vendor ID: Open System Consultants (9048)
            VSA: t=Unknown-Attribute(18) l=29 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                Type: 18
                Length: 29
                Unknown-Attribute: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
        AVP: t=Vendor-Specific(26) l=12 vnd=Check Point Software Technologies Ltd(2620)
            Type: 26
            Length: 12
            Vendor ID: Check Point Software Technologies Ltd (2620)
            VSA: t=Unknown-Attribute(230) l=6 val=00000001
                Type: 230
                Length: 6
                Unknown-Attribute: 00000001
        AVP: t=Message-Authenticator(80) l=18 val=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
            Type: 80
            Length: 18
            Message-Authenticator: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
```
- Debugs for the relevant daemon show the following errors:

`check_respond_msg_auth: Comparison result: 1`

`act_on_response(rp=xxxxxx): Message-Authenticator integrity failed, also happened x times before`

## Cause
The hotfix that addresses [Check Point's Response to CVE-2024-3596 - Blast-RADIUS attack](https://support.checkpoint.com/results/sk/sk182516) expects the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets when present.

This decision was based on the verbiage contained in the RFC draft [Deprecating Insecure Practices in RADIUS](https://www.ietf.org/archive/id/draft-ietf-radext-deprecating-radius-02.html) published by the IETF.

However, RFC3579 "RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)" does not define a strict requirement for the Message-Authenticator to be the first attribute value pair contained in RADIUS response packets.

## Solution
**For Gaia appliances:**

This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 36
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 111
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 177

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

**For Gaia Embedded appliances:**

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:
1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2025-03-13

Last Modified: 2025-09-29
