# radius

Source: https://startwithidentity.com/glossary/radius/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

RADIUS (Remote Authentication Dial-In User Service) is a protocol, defined in [RFC 2865](https://www.rfc-editor.org/rfc/rfc2865), that network devices such as switches, wireless controllers and VPN gateways use to ask a central server whether a user or device may connect, and with what access.

RADIUS sits underneath most enterprise Wi-Fi and wired 802.1X, VPN sign-in and network device administration, with servers such as Cisco ISE, Microsoft NPS and FreeRADIUS making the decisions and often consulting Active Directory. Each network device shares a secret with the server, and classic RADIUS over UDP protects responses with MD5-based checks; the 2024 Blast-RADIUS attack (CVE-2024-3596) showed those responses could be forged by an attacker in the network path, and the recommended mitigations are requiring the Message-Authenticator attribute and moving to RADIUS over TLS (RadSec). The server itself is tier-zero infrastructure: it decides who gets on the network and holds the secrets every device trusts, which is why the [exploited Cisco ISE flaw](https://startwithidentity.com/blog/2026-09-17-cisco-ise-cvss-10-auth-bypass-exploited-as-a-zero-day/) in September 2026 was an identity incident, not just a patch.

See also: [LDAP](https://startwithidentity.com/glossary/ldap/), [Active Directory](https://startwithidentity.com/glossary/active-directory/), [ZTNA](https://startwithidentity.com/glossary/ztna/), [federation](https://startwithidentity.com/glossary/federation/)
