<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama  and PANOS  RADIUS Authentication Failing after upgrade to 10.2 in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-and-panos-radius-authentication-failing-after-upgrade/m-p/593045#M2413</link>
    <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191836"&gt;@BKRogers&lt;/a&gt;!&lt;BR /&gt;Found no mention of this behavior change in release notes or known issues.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 18:09:02 GMT</pubDate>
    <dc:creator>fwmike2</dc:creator>
    <dc:date>2024-07-25T18:09:02Z</dc:date>
    <item>
      <title>Panorama  and PANOS  RADIUS Authentication Failing after upgrade to 10.2</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-and-panos-radius-authentication-failing-after-upgrade/m-p/526016#M1302</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thought I would pass on this solution I found.&amp;nbsp; After upgrading our Panorama from 10.1 to 10.2, our RADIUS authentication no longer worked.&amp;nbsp; The root cause was our Microsoft RADIUS server was using TLS 1.0 for the PEAP-MSCHAP TLS handshake and 10.2 REQUIRES TLS 1.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution is to add the following registry setting to your Microsoft NPS server&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RasMan\PPP\EAP\13&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;add a DWORD&amp;nbsp;&lt;STRONG&gt;TlsVersion&amp;nbsp;&lt;/STRONG&gt;with a hex value of 0x3C0&lt;/P&gt;
&lt;P&gt;then reboot.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This value will allow the MS NPS server to negotiate TLS 1.0 and TLS 1.1.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You probably DONT want to enable TLS 1.2 yet.&amp;nbsp; I found enabling TLS 1.2 will cause 10.1 PANOS to fail the RADIUS handshake.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Related MS Link&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/topic/microsoft-security-advisory-update-for-microsoft-eap-implementation-that-enables-the-use-of-tls-october-14-2014-d9ba4b83-b4e9-2c01-83a7-e42706e671af" target="_blank"&gt;Microsoft security advisory: Update for Microsoft EAP implementation that enables the use of TLS: October 14, 2014 - Microsoft Support&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 15:24:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-and-panos-radius-authentication-failing-after-upgrade/m-p/526016#M1302</guid>
      <dc:creator>BKRogers</dc:creator>
      <dc:date>2023-01-05T15:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama  and PANOS  RADIUS Authentication Failing after upgrade to 10.2</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-and-panos-radius-authentication-failing-after-upgrade/m-p/593045#M2413</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191836"&gt;@BKRogers&lt;/a&gt;!&lt;BR /&gt;Found no mention of this behavior change in release notes or known issues.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 18:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/panorama-and-panos-radius-authentication-failing-after-upgrade/m-p/593045#M2413</guid>
      <dc:creator>fwmike2</dc:creator>
      <dc:date>2024-07-25T18:09:02Z</dc:date>
    </item>
  </channel>
</rss>

