Port 1812: Remote Authentication Dial In User Service (authentication)
UDP 1812 is the officially assigned RADIUS authentication port (RFC 2865); accounting uses 1813. RFC 2865 notes that early deployments used UDP 1645, and Microsoft still lists 1645 and 1646 as legacy RADIUS ports for its Internet Authentication Service. RADIUS carries authentication requests from a Network Access Server (NAS), acting as the client, to a central server.
Port Details
Security Exposure
Classic RADIUS over UDP relies on an MD5-based construction and a shared secret to authenticate server responses. The Blast-RADIUS research (CVE-2024-3596) showed that an attacker who can intercept and modify RADIUS/UDP traffic can forge an Access-Accept by combining a protocol flaw with an MD5 chosen-prefix collision. The researchers note that sending RADIUS/UDP over the open internet is discouraged but still happens in practice.
Hardening
- +Upgrade RADIUS servers first, then clients and network access servers, to versions that send and require the Message-Authenticator attribute.
- +Configure both sides to require Message-Authenticator on all requests and responses, as the Blast-RADIUS mitigation guidance advises.
- +Move RADIUS traffic that crosses untrusted networks to RADIUS over TLS (RadSec, TCP 2083, RFC 6614).
- +Allow UDP 1812 and 1813 only between known network access servers and the RADIUS servers, and use long random shared secrets.
Monitoring
Log Access-Reject volumes per client and alert on RADIUS packets from addresses that are not configured clients. Track which network access servers send requests without the Message-Authenticator attribute.
Tools for Auditing and Monitoring RADIUS
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
Is RADIUS port 1812 TCP or UDP?→
RADIUS uses UDP 1812 for authentication and UDP 1813 for accounting. RADIUS over TLS (RadSec) runs on TCP 2083.
What is the difference between ports 1812 and 1645?→
RFC 2865 explains that early RADIUS deployments used UDP 1645, which conflicts with another service, and that 1812 is the officially assigned port. Some systems still accept 1645 and 1646 for compatibility.
What is Blast-RADIUS?→
Blast-RADIUS (CVE-2024-3596) is an attack on RADIUS/UDP that forges server responses using an MD5 collision. The recommended mitigation is to require the Message-Authenticator attribute and, longer term, to carry RADIUS inside TLS.
Sources
- IANA Service Name and Transport Protocol Port Number Registry: port 1812
- RFC 2865: Remote Authentication Dial In User Service (RADIUS)
- RFC 6614: Transport Layer Security (TLS) Encryption for RADIUS
- Blast-RADIUS: RADIUS/UDP Considered Harmful
- Microsoft Learn: Service overview and network port requirements for Windows
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1812 is not guaranteed to be RADIUS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).