How to decrypt RADIUS traffic using Wireshark with RSA Authentication Manager
Originally Published: 2017-05-19
Last Modified: 2026-06-03
Article Number
Applies To
RSA Product/ Service Type: Authentication Manager
RSA Version/Condition: 7.x, 8.1, 8.0, 8.1
Issue
Resolution
You must know the RADIUS shared secret used in order to decrypt the packets.
You can follow the below steps to be able to decrypt the Radius Packets:
- Capture RADIUS authentication traffic. See Using tcpdump to troubleshoot authentication issues with RSA Authentication Manager 8.x for more information.
- Launch the Wireshark app.
- Open the capture of of the RADIUS traffic, typically in .pcap format.
- Go to Edit > Preferences.
- Click the + next to Protocols to expand the tree.
- Scroll down and select RADIUS.
- Key in the RADIUS shared secret and click Apply.
- The passcode in clear text.
The packet capture before entering the RADIUS shared secret:
The packet capture after entering the RADIUS shared secret:
Related Articles
RADIUS shared secret limitations of RADIUS clients configured with RSA Authentication Manager 759Number of Views aservers occasionally are unable to decrypt tokens from other aservers. 22Number of Views Enable RADIUS debug/verbose logs with all versions of RSA Authentication Manager 8.x 1.95KNumber of Views Adding a Palo Alto RADIUS dictionary to RSA RADIUS for RSA Authentication Manager 8.x 816Number of Views Performing RADIUS authentication tests with NTRadPing to RSA Authentication Manager 8.39KNumber of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?