<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: potential issue with RADIUS traffic passed through Palo devices in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/1219991#M5521</link>
    <description>&lt;P&gt;I was wondering how u overcome this issue.&lt;/P&gt;
&lt;P&gt;Have the same problem with a remote site that needs to access the radius server over Site to site VPN.&lt;/P&gt;
&lt;P&gt;No radius traffic seen on Palo alto at the remote site.&lt;/P&gt;
&lt;P&gt;Checked this article&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLPCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLPCA0 &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and almost sure that Palo Alto (440) drops the packets due MTU size.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 09:30:47 GMT</pubDate>
    <dc:creator>Pieter-Janssens</dc:creator>
    <dc:date>2025-02-11T09:30:47Z</dc:date>
    <item>
      <title>potential issue with RADIUS traffic passed through Palo devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598070#M3753</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a good chance this is not in fact a firewall issue at all.&lt;/P&gt;
&lt;P&gt;But I just wanted to ask people who have more experience than me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone experienced an issue where despite RADIUS traffic being passed through a Palo appliance successfully, RADIUS authentication has still failed?&lt;/P&gt;
&lt;P&gt;The scenario I describe is from Meraki AP's to a windows NPS server on another network. I suspect the issue is with the RADIUS configuration, but just wanted to check.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 04:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598070#M3753</guid>
      <dc:creator>BPSoftware</dc:creator>
      <dc:date>2024-09-18T04:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: potential issue with RADIUS traffic passed through Palo devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598080#M3755</link>
      <description>&lt;P&gt;is this a consistent issue or does it happen randomly?&lt;/P&gt;
&lt;P&gt;you could set up packet-diag filters and packetcapture between 2 hosts for radius connections (bidirectional) to see if anything weird is popping up in the global counters, or any packets are getting moved around by the firewall between ingress and egress&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 07:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598080#M3755</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-09-18T07:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: potential issue with RADIUS traffic passed through Palo devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598179#M3761</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have several types of radius setup flowing through a Palo Alto, no issues, If you think there is an issue, as Reaper mentioned perform a pcap and look at the traffic logs to see if anything was denied. The Palo Alto does not 'change or modify' the packets.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 18:27:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598179#M3761</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-09-18T18:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: potential issue with RADIUS traffic passed through Palo devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598214#M3766</link>
      <description>&lt;P&gt;Hi everyone, thank you for the replies its much appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have narrowed the issue down to my old nemesis MTU size. Correct me if I'm wrong but Palo Alto firewalls like most devices, use 1500 by default, right? I've never specified one previously. Seems like they are fragmenting anything over 1000. Very odd.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 00:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/598214#M3766</guid>
      <dc:creator>BPSoftware</dc:creator>
      <dc:date>2024-09-19T00:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: potential issue with RADIUS traffic passed through Palo devices</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/1219991#M5521</link>
      <description>&lt;P&gt;I was wondering how u overcome this issue.&lt;/P&gt;
&lt;P&gt;Have the same problem with a remote site that needs to access the radius server over Site to site VPN.&lt;/P&gt;
&lt;P&gt;No radius traffic seen on Palo alto at the remote site.&lt;/P&gt;
&lt;P&gt;Checked this article&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLPCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClLPCA0 &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;and almost sure that Palo Alto (440) drops the packets due MTU size.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 09:30:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/potential-issue-with-radius-traffic-passed-through-palo-devices/m-p/1219991#M5521</guid>
      <dc:creator>Pieter-Janssens</dc:creator>
      <dc:date>2025-02-11T09:30:47Z</dc:date>
    </item>
  </channel>
</rss>

