<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RADIUS flows for Authenticating GP with username, password and OTP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-flows-for-authenticating-gp-with-username-password-and/m-p/1242937#M7153</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a working GP configuration that uses client certificate, username and password for authentication, with the username and password validated using PEAP-MSCHAPv2 against a RADIUS server.&lt;/P&gt;
&lt;P&gt;I want to add an OTP challenge as described at&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS," target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS,&lt;/A&gt;&amp;nbsp;for the on demand mode and using RADIUS.&lt;/P&gt;
&lt;P&gt;Related documents describe how to configure the Auth Profile. But it is unclear to me what the RADIUS server needs to do to activate the challenge. A number of sources indicate that after the MSCHAP succeeds, the RADIUS server needs to send an Access-Challenge, but it is unclear if this needs to be inside or outside the EAP context setup for EAP-MSCHAP. Once the challenge has been requested, it is then unclear how the PA as a RADIUS client responds, eg. with PAP or EAP-GTC.&lt;BR /&gt;Does anyone have a working setup like this and can share details of how the RADIUS server needs to respond?&lt;/P&gt;
&lt;P&gt;Target is the PA3220 but I'm initially testing on a PA-VM, all running 11.1.10-h1.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Dec 2025 04:52:52 GMT</pubDate>
    <dc:creator>DanielKirkham</dc:creator>
    <dc:date>2025-12-02T04:52:52Z</dc:date>
    <item>
      <title>RADIUS flows for Authenticating GP with username, password and OTP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-flows-for-authenticating-gp-with-username-password-and/m-p/1242937#M7153</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a working GP configuration that uses client certificate, username and password for authentication, with the username and password validated using PEAP-MSCHAPv2 against a RADIUS server.&lt;/P&gt;
&lt;P&gt;I want to add an OTP challenge as described at&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS," target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8ICAS,&lt;/A&gt;&amp;nbsp;for the on demand mode and using RADIUS.&lt;/P&gt;
&lt;P&gt;Related documents describe how to configure the Auth Profile. But it is unclear to me what the RADIUS server needs to do to activate the challenge. A number of sources indicate that after the MSCHAP succeeds, the RADIUS server needs to send an Access-Challenge, but it is unclear if this needs to be inside or outside the EAP context setup for EAP-MSCHAP. Once the challenge has been requested, it is then unclear how the PA as a RADIUS client responds, eg. with PAP or EAP-GTC.&lt;BR /&gt;Does anyone have a working setup like this and can share details of how the RADIUS server needs to respond?&lt;/P&gt;
&lt;P&gt;Target is the PA3220 but I'm initially testing on a PA-VM, all running 11.1.10-h1.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 04:52:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/radius-flows-for-authenticating-gp-with-username-password-and/m-p/1242937#M7153</guid>
      <dc:creator>DanielKirkham</dc:creator>
      <dc:date>2025-12-02T04:52:52Z</dc:date>
    </item>
  </channel>
</rss>

