# Bind NPS RADIUS traffic to the intended network interfaces

> Which interfaces and UDP ports should an NPS server use for RADIUS?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-181-bind-nps-radius-traffic-to-the-intended-network-interfaces/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:10+00:00
- Modified: 2026-09-08T18:26:32+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which interfaces and UDP ports should an NPS server use for RADIUS?

## Potentially affected

Administrators configuring Network Policy Server on a multihomed Windows server.

## DSE recommendation

Write an interface-and-port matrix before changing the NPS Ports settings.

## Article

## Source facts

By default, NPS listens for IPv4 and IPv6 RADIUS traffic on every installed network adapter using ports 1812, 1813, 1645, and 1646. Administrators can specify particular adapters when they need to exclude an interface from RADIUS traffic. Microsoft requires access servers to use the same RADIUS port numbers as NPS and notes that some devices use the older 1645 and 1646 defaults. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-multihomed-configure).

## Applicability

Inventory the server interfaces, their intended purpose, and the authentication and accounting ports configured on each access device. Treat IPv4 and IPv6 as explicit entries. Do not infer that an adapter intended only for management is excluded from NPS listening.

## DSE recommendation

Write an interface-and-port matrix before changing the NPS Ports settings. Include the exact local address, protocol family, request type, and permitted access devices. Have the network owner compare it with the corresponding device settings and firewall rules. Preserve the original configuration and pilot one access path before changing all devices. Define how operators will recover access if the expected listener is unavailable.

## Verification

Send controlled authentication and accounting requests from representative access devices and confirm their arrival on the intended interface. Check an excluded interface as a negative case. Record listener settings, device port values, and correlated results; investigate a silent accounting path separately from a successful sign-in.

## Official references

[Microsoft Learn: Configure NPS on a Multihomed Computer](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-multihomed-configure). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure NPS on a Multihomed Computer
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-multihomed-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Bind NPS RADIUS traffic to the intended network interfaces,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-181-bind-nps-radius-traffic-to-the-intended-network-interfaces/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
