Validate the complete firewall path for RADIUS requests and replies

Which firewall paths must work between RADIUS clients, proxies, and NPS?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Which firewall paths must work between RADIUS clients, proxies, and NPS?

Potentially affected

Network administrators reviewing firewall rules for an NPS-based RADIUS deployment.

DSE recommendation

Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path.

Source facts

Microsoft warns that incorrectly filtered RADIUS traffic between access clients, proxies, and servers can prevent network authentication. The documented default NPS UDP ports are 1812, 1813, 1645, and 1646, with local firewall exceptions normally configured during installation. For Windows Server 2019, Microsoft requires changing the IAS service security identifier for that firewall exception; without the change, RADIUS traffic is dropped. For additional restriction, the source describes filtering with the individual RADIUS clients’ addresses rather than an unrestricted set of senders. Microsoft Learn.

Applicability

Identify every firewall crossed by the actual RADIUS path and record the configured authentication and accounting ports. Review the source’s operating-system-specific notes for the NPS server. Keep local listener selection separate from the network rules that permit requests and responses.

DSE recommendation

Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path. Have both the access-device and firewall owners compare their settings against the same matrix. Preserve the existing rules and pilot one device before broad deployment. Treat an unnecessary source range or open port as a design question requiring an explicit owner.

Verification

Generate a controlled authentication request and a corresponding accounting event where applicable. Correlate device, firewall, and NPS observations to show that both required directions pass. Test a sender that should be excluded. Investigate accounting loss independently from authentication success and record the actual rule responsible for each observed path.

Official references

Microsoft Learn: Configure Firewalls for RADIUS Traffic. Source reviewed September 8, 2026.

Primary reference

Review the official source

Configure Firewalls for RADIUS Traffic · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE