<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Sequence problem in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541895#M1252</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/166658"&gt;@boblin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That guide doesn't have you modifying the authentication timeout value which will cause this behavior. By default GlobalProtect's timeout is 30 seconds, you'll need to adjust things a bit to account for the delay being introduced by the authentication sequence and the down host.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2023 19:00:44 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-05-11T19:00:44Z</dc:date>
    <item>
      <title>Authentication Sequence problem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541802#M1249</link>
      <description>&lt;P&gt;I configured DUO Proxy for GloablProtect&amp;nbsp;MFA redundancy on our PA 850 firewall using&amp;nbsp;Authentication Sequence. This post shows how I configured:&amp;nbsp;&lt;A href="http://www.howtonetworking.com/blog/2023/04/17/how-do-we-configure-two-duo-proxy-servers-for-palo-alto-firewall/" target="_blank"&gt;Configure two duo proxy servers for Palo alto firewall MFA redundancy – Net/PC How to (howtonetworking.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem I have is when the top Authentication profile or DUO Proxy server is down, then the user can't login to GloablProtect. The DUO Proxy server and PA authentication profile is not the issue because I can run the test command successfully.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="wp-block-preformatted"&gt;&lt;STRONG&gt;test authentication authentication-&lt;SPAN class="IL_AD"&gt;profile&lt;/SPAN&gt; &lt;VAR&gt;&amp;lt;authentication-profile-name&amp;gt;&lt;/VAR&gt; username &lt;VAR&gt;&amp;lt;username&amp;gt;&lt;/VAR&gt; password&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;DIV id="tinyMceEditorboblin_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;Alos, if I move the second profile (DUO Authentication-2 in my example) to the top, it works.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="boblin_1-1683767742215.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50121i636F5963B9028CF3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="boblin_1-1683767742215.png" alt="boblin_1-1683767742215.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The problem is if the top authentication DUO proxy server (DUO Authentication-2) is down, no one can't login. &amp;nbsp;MONITOR&amp;gt;Logs&amp;gt;System doesn't have authentication information. If I move the second authentication profile (DUO Authentication in my example) to the top, then it works again. I think it is&amp;nbsp;Authentication Sequence problem but can't figure out how to fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 01:29:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541802#M1249</guid>
      <dc:creator>boblin</dc:creator>
      <dc:date>2023-05-11T01:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sequence problem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541895#M1252</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/166658"&gt;@boblin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That guide doesn't have you modifying the authentication timeout value which will cause this behavior. By default GlobalProtect's timeout is 30 seconds, you'll need to adjust things a bit to account for the delay being introduced by the authentication sequence and the down host.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 19:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541895#M1252</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-05-11T19:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sequence problem</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541927#M1260</link>
      <description>&lt;P&gt;I fixed the problem by adjusting the timeout. Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 21:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/authentication-sequence-problem/m-p/541927#M1260</guid>
      <dc:creator>boblin</dc:creator>
      <dc:date>2023-05-11T21:25:10Z</dc:date>
    </item>
  </channel>
</rss>

