What you need to know
Which firewall paths must work between RADIUS clients, proxies, and NPS?
Potentially affected
Network administrators reviewing firewall rules for an NPS-based RADIUS deployment.
DSE recommendation
Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path.
Source facts
Microsoft warns that incorrectly filtered RADIUS traffic between access clients, proxies, and servers can prevent network authentication. The documented default NPS UDP ports are 1812, 1813, 1645, and 1646, with local firewall exceptions normally configured during installation. For Windows Server 2019, Microsoft requires changing the IAS service security identifier for that firewall exception; without the change, RADIUS traffic is dropped. For additional restriction, the source describes filtering with the individual RADIUS clients’ addresses rather than an unrestricted set of senders. Microsoft Learn.
Applicability
Identify every firewall crossed by the actual RADIUS path and record the configured authentication and accounting ports. Review the source’s operating-system-specific notes for the NPS server. Keep local listener selection separate from the network rules that permit requests and responses.
DSE recommendation
Build a rule matrix naming each client or proxy address, NPS endpoint, request type, UDP port, and return path. Have both the access-device and firewall owners compare their settings against the same matrix. Preserve the existing rules and pilot one device before broad deployment. Treat an unnecessary source range or open port as a design question requiring an explicit owner.
Verification
Generate a controlled authentication request and a corresponding accounting event where applicable. Correlate device, firewall, and NPS observations to show that both required directions pass. Test a sender that should be excluded. Investigate accounting loss independently from authentication success and record the actual rule responsible for each observed path.
Official references
Microsoft Learn: Configure Firewalls for RADIUS Traffic. Source reviewed September 8, 2026.
Review the official source
Configure Firewalls for RADIUS Traffic · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE