I was hoping for a better answer, but here is what is going on. This is Blast-RADIUS related. sk183244
Basically, our RADIUS server, Imprivata, is not sending the AVP Message-Authenticator back first. Check Point is requiring that the Message-Authenticator AVP is listed first in the response, since it is not first, we get the failure. We have a ticket open with Imprivata, and they are investigating the issue, so it sounds like we are not the first ticket on this.
Here are pictures explaining the issue. You can see in the Access-Request, Message-Authenticator is AVP #1, in Access-Accept it is AVP #3, which to Check Point is bad.


Per the SK I linked, it sounds like there is a patch that changes the behavior, but that hotfix is currently only available for JHF-96,98. Nothing for JHF-99 yet.
So, it seems like I am still stuck running JHF-89 for the foreseeable future.