How RADIUS Authentication Works - and Why We Handle It for You

When a user connects to their PrivyNet node, the authentication request is forwarded to your RADIUS server, validated against your identity store, and the result returned - transparently, in seconds

User Device
User enters credentials on their device
IKEv2 Tunnel
Credentials travel through an encrypted IKEv2 tunnel
PrivyNet Node
Dedicated node forwards the auth request to your RADIUS server
RADIUS Server
Your RADIUS server validates credentials against your identity store
Identity Store
Active Directory, FreeRADIUS, or any RADIUS-compatible provider

RADIUS is already configured in PrivyNet's infrastructure. Your organisation only needs to point PrivyNet at your RADIUS server IP and provide the shared secret - there is no VPN-side configuration work required.

What Pre-Configured RADIUS Authentication Means in Practice

The operational impact of delegating authentication to your existing identity infrastructure

No Separate Credential Store

Your team uses the same credentials they use for everything else. No extra passwords, no separate VPN user accounts to provision or maintain.

Centralised Policy Enforcement

Access rules, group policies, and account lockouts configured in your identity provider apply automatically to VPN access - no duplication required.

Instant Offboarding

Disable a user in Active Directory and their VPN access is revoked at the next authentication attempt. No separate step needed in PrivyNet.

Zero VPN-Side Configuration

RADIUS is pre-configured in PrivyNet's infrastructure. Your IT team provides the RADIUS server details - PrivyNet handles the rest.

Works With Your Existing Identity Infrastructure

PrivyNet's RADIUS authentication is compatible with any standards-compliant RADIUS server or proxy. If your identity provider supports RADIUS or has a RADIUS agent, it will work with PrivyNet.

Identity InfrastructureHow It Works With PrivyNet
Windows Active Directory + NPS
NPS acts as the RADIUS server and validates credentials directly against Active Directory. The most common enterprise setup - no additional software required.
FreeRADIUS
Open-source RADIUS server - configure as the RADIUS endpoint. Supports a wide range of back-end identity stores including LDAP and SQL.
Cisco ISE
Enterprise-grade RADIUS server with native policy enforcement. Connects to PrivyNet as a standard RADIUS client - works as-is.
Azure AD (via NPS Extension)
The NPS Extension for Azure AD bridges Azure AD (including MFA) to RADIUS. Supports Azure AD Conditional Access policies on VPN connections.
Okta (via RADIUS Agent)
The Okta RADIUS Agent exposes Okta as a RADIUS endpoint. Supports Okta MFA flows for VPN authentication.
Google Workspace (via proxy)
Use a RADIUS proxy that supports Google Workspace authentication. Any RADIUS-compatible proxy that bridges to your identity provider will work.

What Setup Looks Like on Your Side

Three values. That is all your IT team needs to provide. PrivyNet handles everything else.

Your RADIUS Server IP or Hostname

Provide the IP address or hostname of your RADIUS server. This is the only endpoint PrivyNet needs to forward authentication requests.

The Shared Secret

Provide the shared secret that authenticates the RADIUS client (the PrivyNet node) to your RADIUS server. This is a standard RADIUS configuration value.

UDP Port 1812 Open

Confirm that UDP port 1812 is open from the PrivyNet VPN node's static IP to your RADIUS server. If you use RADIUS accounting, also open UDP 1813.

PrivyNet handles the RADIUS client configuration on the VPN node - it is pre-built into the infrastructure. If your RADIUS server also supports accounting (UDP 1813), session data can be fed directly into your existing log aggregation.

Frequently Asked Questions

Common questions about RADIUS authentication on PrivyNet

Does PrivyNet support RADIUS authentication?

Yes. PrivyNet's dedicated VPN infrastructure uses RADIUS authentication over IKEv2. It is pre-configured as part of every deployment - your team provides the RADIUS server details and PrivyNet handles the rest.

Do I need to configure RADIUS on my PrivyNet VPN node?

No. RADIUS authentication is pre-configured in PrivyNet's infrastructure. You provide your RADIUS server IP address and shared secret - there is no VPN-side configuration required from your team.

Which RADIUS servers are compatible with PrivyNet?

PrivyNet works with any standards-compliant RADIUS server, including Windows NPS (for Active Directory), FreeRADIUS, Cisco ISE, and cloud identity providers that expose a RADIUS endpoint such as Okta (via RADIUS Agent) or Azure AD (via NPS Extension).

If a user is disabled in Active Directory, does their VPN access get revoked?

Yes. Because authentication is delegated to your RADIUS server and identity store, disabling a user in Active Directory prevents them from authenticating on their next VPN connection attempt. No separate step is required in PrivyNet.

What ports need to be open for RADIUS to work?

UDP port 1812 must be open between the PrivyNet VPN node's static IP and your RADIUS server. If you are using RADIUS accounting, UDP port 1813 should also be open.

Can PrivyNet work alongside our existing MFA setup?

Yes. If your identity provider supports MFA through RADIUS - for example Azure AD via the NPS Extension, or Okta via the RADIUS Agent - your existing MFA policies will apply to VPN authentication automatically. No additional configuration is needed on the PrivyNet side.

Enterprise Authentication, Without the Enterprise Setup Overhead

RADIUS authentication is pre-configured in every PrivyNet deployment. Provide your RADIUS server details and your team is connected through your existing identity infrastructure - no VPN-side configuration required.

RADIUS pre-configured
Works with Active Directory
Zero VPN-side setup