Decrypt RADIUS traffic using Wireshark

 

Issue

This article explains how to decrypt RADIUS traffic captured by Wireshark when having authentication issues.  Steps in this article explain how to decrypt the traffic to be able to see the username and passcode in plain text.

Resolution

You must know the RADIUS shared secret used in order to decrypt the packets.

You can follow the below steps to be able to decrypt the Radius Packets:
  1. Capture RADIUS authentication traffic.  
  2. Launch the Wireshark app.
  3. Open the capture of of the RADIUS traffic, typically in .pcap format.
  4. Go to Edit > Preferences.
  5. Click the + next to Protocols to expand the tree.
  6. Scroll down and select RADIUS.
  7. Key in the RADIUS shared secret and click Apply.
  8. The passcode in clear text.

Comments

Popular posts from this blog

Firepower FMC and FTD troubleshooting

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.