Help with NTLM_AUTH and a Fortigate
Alan DeKok
aland at deployingradius.com
Tue Jun 3 10:37:47 UTC 2025
On Jun 2, 2025, at 9:23 PM, Matthew Beechey <mobiusnz at gmail.com> wrote:
>
> Ok - I've removed freeradius and freeradius-config and reinstalled to get a
> default config back. I've gone ahead and edited the files again from
> scratch following instructions. Again a NTRadPint with the default entry
> for NTLM in works - With that off it fails which I guess is to be expected
> as I see NTRadPing doesn't specify and auth type and the only option is
> CHAP not MSCHAP.
>
> With Radtest I get
You've been told that the client output isn't helpful. Why are you still posting it?
> In the debug I can see
>
> mschap: Found MS-CHAP attributes. Setting 'Auth-Type = mschap'
> (0) [mschap] = ok
There's a lot more debug output than that.
You've been told to read the documentation:
https://wiki.freeradius.org/list-help
Which says exactly what to do.
Why are you not following the documentation? Why are you asking for help, and then not following the guidance that you are given?
> Which I was failing on previously due to a bad edit somewhere.
It was failing due to a bad *method*. You changed things you didn't understand, without reading the documentation. It wasn't an accidental edit. It was a deliberate choice to do the wrong thing.
Like being told to read the documentation and follow instructions... and then not doing that.
> I apologise for being back here again - I feel that I'm 99.9% there and I'm
> just missing some small step.
You're making random changes without really understanding what the changes are, or why you're making them.
There is documentation. We can help. But not if you refuse to read the documentation and do what it says.
At this point, I can't answer any more questions until you read the wiki page I posted above, and follow the instructions.
Alan DeKok.
More information about the Freeradius-Users
mailing list