Skip to content

BlastRadius mitigations causing multiple events when 'requiremsgauth' flag is set for Remote Servers  #10

Open
@andrew-fitzgerald

Description

Event Code 4420
EVENT: The RADIUS Proxy received a response from server 127.0.0.1 with a missing Message-Authenticator attribute. Response is currently allowed since the requireMsgAuth is configured in Audit mode. See https://support.microsoft.com/help/5040268 to learn more.
EVENT DESCRIPTION:
This is an Audit event for RADIUS response packets received without the Message-Authenticator attribute at the proxy. Consider changing the specified RADIUS server for the Message-Authenticator attribute. The RADIUS packet will be dropped once the requiremsgauth configuration is enabled.

The above event fires when the PAN-RA proxy RADIUS Remote Server has the attribute 'requiremsgauth' enabled

Workaround includes adding the PANRRA proxy from Remote Servers to the exception list which will stop the events from firing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions