<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Auth VIA management? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594509#M5653</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31972"&gt;@tcsmithh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In the service routes config you can specify source interface per service, or per destinantion.&lt;/P&gt;
&lt;P&gt;If you define source interface for RADIUS service, this will force the firewall to use the same interface for every RADIUS server you define.&lt;/P&gt;
&lt;P&gt;Specifying source interface per destination allow you to have different RADIUS servers reachable from different interfaces/VRs&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 15:42:33 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2024-08-09T15:42:33Z</dc:date>
    <item>
      <title>Radius Auth VIA management?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594146#M5635</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;i have a GP portal and Gateway configured for radius auth in vr2 with just connected and a default route. vr1 has the routes to the radius server. my question is, can i send the auth requests via the management port?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 14:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594146#M5635</guid>
      <dc:creator>tcsmithh</dc:creator>
      <dc:date>2024-08-06T14:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Auth VIA management?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594181#M5639</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31972"&gt;@tcsmithh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;By default Palo Alto firewall will always use the dedicated management interface for services like authentication servers, DNS, NTP etc.&lt;/P&gt;
&lt;P&gt;When you configure your RADIUS server, firewall will try to reach it over the dedicated management interface. Note that this traffic does not pass over the firewall policy, nor perform route look with any VR (virtual-router), it just uses the management default route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If FW management network does not have access to RADIUS server you can tell the firewall to use one of the dateplane interface, by changing the relevant service route - &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes/service-routes-overview" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes/service-routes-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;With service routes you basically tell the firewall which dataplane interface to use as source interface. After that the traffic will perform route lookup - against the VR associated with source interface - to determine the next hop.Traffic will also pass over the security policy, so if your policy is very restrictive you need to make sure it is allowed&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 19:39:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594181#M5639</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-06T19:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Auth VIA management?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594506#M5651</link>
      <description>&lt;P&gt;thank you very much, i was certain that was the case, but wanted verification....unless i do custom routing.... thanks again&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 14:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594506#M5651</guid>
      <dc:creator>tcsmithh</dc:creator>
      <dc:date>2024-08-09T14:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Auth VIA management?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594509#M5653</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/31972"&gt;@tcsmithh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;In the service routes config you can specify source interface per service, or per destinantion.&lt;/P&gt;
&lt;P&gt;If you define source interface for RADIUS service, this will force the firewall to use the same interface for every RADIUS server you define.&lt;/P&gt;
&lt;P&gt;Specifying source interface per destination allow you to have different RADIUS servers reachable from different interfaces/VRs&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 15:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-auth-via-management/m-p/594509#M5653</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-09T15:42:33Z</dc:date>
    </item>
  </channel>
</rss>

