AuthHound

RADIUS & NPS error library

Each page explains one failure signature the way a colleague would: what it actually means, why it happens, and the exact next thing to check.

Windows NPS reason codes

A reference to Windows NPS Event 6273 reason codes — the numbers in the Network Policy Server log when authentication is rejected. Each code below links to what it actually means and the first thing to check.

FreeRADIUS: EAP, TLS & certificates

A FreeRADIUS error reference for the EAP-TLS handshake: the certificate, TLS-alert, and EAP-fragmentation failures you see in radiusd -X output, with the exact log line and how to read it.

FreeRADIUS: authentication & clients

FreeRADIUS authentication and client errors — rejected logins, MSCHAP mismatches, LDAP bind failures, and unknown-client messages — explained with the concrete next check for each.

Authorization, VLANs & enforcement

The failures that happen after the login succeeds: the Access-Accept was returned, but the VLAN, ACL, role, or session keys didn't take. Dynamic VLAN not applied, Filter-Id ignored, MAC Auth Bypass not matching, and MPPE keys stripped in transit — why an authenticated device still can't get on the network.

Connectivity & timeouts

When the RADIUS server never logs the request at all: timeouts and silent failures in the network path between the client and the server, and how to prove where the packets are dying.

Guides

Longer-form guides for the migrations and design decisions behind these failures — the background that turns a one-off fix into a change that holds.

Staring at a log right now?

Skip the reading — paste it into the analyzer and get the diagnosis for your specific log in seconds. It runs in your browser; nothing is uploaded.