# Validate the complete firewall path for RADIUS requests and replies

> Which firewall paths must work between RADIUS clients, proxies, and NPS?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-205-validate-the-complete-firewall-path-for-radius-requests-and-replies/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:46+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Which firewall paths must work between RADIUS clients, proxies, and NPS?

## Potentially affected

Network administrators reviewing firewall rules for an NPS-based RADIUS deployment.

## DSE recommendation

Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path.

## Article

## Source facts

Microsoft warns that incorrectly filtered RADIUS traffic between access clients, proxies, and servers can prevent network authentication. The documented default NPS UDP ports are 1812, 1813, 1645, and 1646, with local firewall exceptions normally configured during installation. For Windows Server 2019, Microsoft requires changing the IAS service security identifier for that firewall exception; without the change, RADIUS traffic is dropped. For additional restriction, the source describes filtering with the individual RADIUS clients’ addresses rather than an unrestricted set of senders. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-firewalls-configure).

## Applicability

Identify every firewall crossed by the actual RADIUS path and record the configured authentication and accounting ports. Review the source’s operating-system-specific notes for the NPS server. Keep local listener selection separate from the network rules that permit requests and responses.

## DSE recommendation

Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path. Have both the access-device and firewall owners compare their settings against the same matrix. Preserve the existing rules and pilot one device before broad deployment. Treat an unnecessary source range or open port as a design question requiring an explicit owner.

## Verification

Generate a controlled authentication request and a corresponding accounting event where applicable. Correlate device, firewall, and NPS observations to show that both required directions pass. Test a sender that should be excluded. Investigate accounting loss independently from authentication success and record the actual rule responsible for each observed path.

## Official references

[Microsoft Learn: Configure Firewalls for RADIUS Traffic](https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-firewalls-configure). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Firewalls for RADIUS Traffic
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-firewalls-configure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Validate the complete firewall path for RADIUS requests and replies,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-205-validate-the-complete-firewall-path-for-radius-requests-and-replies/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
