09-25-2026 02:11 AM
Hi everyone,
Some time ago, I configured an SSID using 802.1X authentication with NPS, and it has been working correctly.
Now, I need to add a new SSID to the same NPS server. In this case, the computer that will connect to the SSID is not joined to the domain.
I created a new Network Policy in NPS and placed it at the top of the policy list. The conditions are:
The complete IP range is already configured under RADIUS Clients.
However, when I try to connect to the Wi-Fi network, I receive the following error in the NPS Event Viewer:
An Access-Request message was received from RADIUS client x.x.x.x with a Message-Authenticator attribute that is not valid.
I have been reading about this error, and several posts suggest that it may be related to an incorrect shared secret.
I have checked the shared secret and it seems to be correct. Nevertheless, to rule this out, I created a new RADIUS client containing only this AP and configured a completely new shared secret on both sides, Meraki and NPS.
Unfortunately, I still receive exactly the same error.
Has anyone experienced this issue before or have any idea what else I could check?
Thanks in advance.
09-25-2026 06:35 AM
Another thing that caught my attention is that you mentioned these users aren't in the domain, right? How do you expect NPS to validate these users?
Are they local users on the server? If NPS doesn't recognize the user base, this configuration won't work.
09-25-2026 06:38 AM
Just a quick thought to share on the shared secret thing. Sometimes you might be using a character that is not supported by one or both devices and there is no specific message to help you with knowing that. Try to use a very simple shared secret and see if that works. If so, try to use a complex one with some standard symbols such as the ! and @.
09-28-2026 11:18 PM
I am using the same shared secret for another SSID, and it is working correctly.
For this reason, I am 100% sure that the shared secret is correct. i made this ssdi long time ago hahahaha
I could try changing it to a new, simpler shared secret just for testing, but I don't think the password itself is the problem, since the other SSID is currently working with the same one.
09-29-2026 02:23 AM
Makes sense, but probably I would still do it :). Also, if you could please share your redacted screenshots for review.
09-29-2026 02:56 AM
I would focus on Event ID 18 first. This means NPS is rejecting the RADIUS request while validating the Message Authenticator, so I would not spend much time changing the Network Policy yet.
Since you already tested the AP as a /32 RADIUS client with a new shared secret, I would capture one RADIUS request from the working SSID and one from the new SSID in Wireshark and compare them.
Check the source IP, Message Authenticator and the other RADIUS attributes being sent by the Meraki AP.
I would also check the Meraki RADIUS settings for the new SSID and see what Called Station ID and NAS ID are actually being sent.
The VLAN and the PC not being domain joined should not cause a Message Authenticator validation error. I would resolve that error first and then look at the Network Policy matching.
09-29-2026 04:44 AM - edited 09-29-2026 04:45 AM
Hmm... I’m not sure why I’m receiving this error:
Event ID :16
“A RADIUS message with the Code field set to 12, which is not valid, was received on port 1812 from RADIUS client APs-Meraki-xxx. Valid values of the RADIUS Code field are documented in RFC 2865.”
I’m not sure what could be causing this
09-29-2026 05:03 AM
The combination of "invalid Message-Authenticator" and "Code 12" suggests NPS may be rejecting the RADIUS packet itself rather than the authentication request.
If possible, take a packet capture between the AP and NPS. That will quickly show whether the AP is sending malformed RADIUS packets, Status-Server probes, or something unexpected.
09-29-2026 05:56 AM
- @aleabrahao >....suggests NPS may be rejecting the RADIUS packet itself rather than the authentication request.
That seems indeed true when looking at :
https://community.cisco.com/t5/wireless/a-radius-message-with-the-code-field-set-to-12-which-is-not/m-p/5500172/highlight/true#M301305
M.
09-29-2026 05:54 AM
- @athan1234 FYI : https://community.cisco.com/t5/wireless/a-radius-message-with-the-code-field-set-to-12-which-is-not/m-p/5500172/highlight/true#M301305
M.
09-29-2026 06:28 AM
The Message-Authenticator error can also be caused by an authentication-method or RADIUS configuration mismatch, not only the shared secret. Since you already tested with a new RADIUS client and shared secret, I’d check the Meraki SSID’s 802.1X/EAP settings and NPS policy conditions, especially the EAP method and certificate configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide