<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VWire Radius (NPS) via Mgmt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/458709#M101930</link>
    <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183065"&gt;@annielee&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it be possible try to change interface to any and select management IP address from drop down list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1642145256556.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38649iDCF0396AC6E53023/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1642145256556.png" alt="PavelK_0-1642145256556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, could you please tell me what PAN-OS you are running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jan 2022 07:31:53 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2022-01-14T07:31:53Z</dc:date>
    <item>
      <title>VWire Radius (NPS) via Mgmt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457408#M101815</link>
      <description>&lt;P&gt;Happy 2022 !&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We've just setup VWires for our branches firewalls (A/A Layer 2), no ip address on any interfaces except :&lt;/P&gt;&lt;P&gt;- Mgmt (routable and managed by Panorama)&lt;/P&gt;&lt;P&gt;- HA1-3 (non-routable address)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the device management (SNMP, NTP and etc via Mgmt IP) works fine except for Radius authentication, we did some troubleshooting :&lt;/P&gt;&lt;P&gt;- tested on the firewall with 'test authentication radius' cli and it worked successfully&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when we try to logon to the firewall, it failed and doesnt reach the Radius and upon checking, the firewall is using the HA address as the source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Might be something i missed, but ive looked everywhere unless this is not supported for VWire design.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 01:24:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457408#M101815</guid>
      <dc:creator>annielee</dc:creator>
      <dc:date>2022-01-07T01:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: VWire Radius (NPS) via Mgmt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457437#M101816</link>
      <description>&lt;P&gt;Thank you for post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183065"&gt;@annielee&lt;/a&gt;&amp;nbsp;and Happy 2022!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have one site running with identical setup (VWire - no interface IP address, A/A HA, Panorama managed). The only difference is I am using TACACS+ instead of RADIUS. From what you have described this should be working and I do not see any reason why this should not be supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please check that management interface is configured under: &lt;STRONG&gt;Device &amp;gt; Setup &amp;gt; Services &amp;gt; Service Route Configuration &amp;gt;&amp;nbsp;Use Management Interface for all&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, could you please check in log:&amp;nbsp;&lt;STRONG&gt;tail follow yes mp-log authd.log&lt;/STRONG&gt; whether it can uncover more details?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 03:56:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457437#M101816</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-07T03:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: VWire Radius (NPS) via Mgmt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457621#M101830</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, ive checked the Service Route and its using Mgmt Interfaces for all. Below are the debug, and it mentioned cannot bind interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.108 +1100 debug: _start_async_auth(pan_auth_&lt;/SPAN&gt;&lt;SPAN&gt;service_handle.c:293): enqueued into not send queue: elapsed secs: 3 (max allowed secs (timeout) 60)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: pan_authd_radius_create_req_&lt;/SPAN&gt;&lt;SPAN&gt;payload(pan_authd_radius.c:&lt;/SPAN&gt;&lt;SPAN&gt;236): username: annielee&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: pan_make_radius_request_buf(&lt;/SPAN&gt;&lt;SPAN&gt;pan_authd_radius_prot.c:398): RADIUS request type: PAP&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: _create_rw_sock(pan_authd_&lt;/SPAN&gt;&lt;SPAN&gt;conn_mgmt.c:1448): create a UDP socket: 15&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 Error: &amp;nbsp;_create_rw_sock(pan_authd_&lt;/SPAN&gt;&lt;SPAN&gt;conn_mgmt.c:1477): Failed to bind to client side sock: errno=126(Cannot assign requested address)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 Error: &amp;nbsp;_create_rw_sock(pan_authd_&lt;/SPAN&gt;&lt;SPAN&gt;conn_mgmt.c:1499): reached max number of retries (3) to connect to server :0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 Error: &amp;nbsp;_try_fd_create_if_not(pan_&lt;/SPAN&gt;&lt;SPAN&gt;authd_conn_mgmt.c:517): _create_rw_sock()&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 Error: &amp;nbsp;pan_authd_conn_mgmt_enqueue_&lt;/SPAN&gt;&lt;SPAN&gt;req(pan_authd_conn_mgmt.c:589)&lt;/SPAN&gt;&lt;SPAN&gt;: _try_fd_create_if_not() for conn context id: 2&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 Error: &amp;nbsp;_start_async_auth(pan_auth_&lt;/SPAN&gt;&lt;SPAN&gt;service_handle.c:283): pan_authd_conn_mgmt_enqueue_&lt;/SPAN&gt;&lt;SPAN&gt;req(): rad req id: 188; seq num: 188 ; authd global id 7044706393709871124&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: _start_async_auth(pan_auth_&lt;/SPAN&gt;&lt;SPAN&gt;service_handle.c:293): enqueued into not send queue: elapsed secs: 3 (max allowed secs (timeout) 60)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: pan_authd_radius_create_req_&lt;/SPAN&gt;&lt;SPAN&gt;payload(pan_authd_radius.c:&lt;/SPAN&gt;&lt;SPAN&gt;236): username: annielee&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: pan_make_radius_request_buf(&lt;/SPAN&gt;&lt;SPAN&gt;pan_authd_radius_prot.c:398): RADIUS request type: PAP&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;2022-01-08 11:38:32.109 +1100 debug: _create_rw_sock(pan_authd_&lt;/SPAN&gt;&lt;SPAN&gt;conn_mgmt.c:1448): create a UDP socket: 15&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 02:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/457621#M101830</guid>
      <dc:creator>annielee</dc:creator>
      <dc:date>2022-01-08T02:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: VWire Radius (NPS) via Mgmt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/458709#M101930</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183065"&gt;@annielee&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it be possible try to change interface to any and select management IP address from drop down list?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1642145256556.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38649iDCF0396AC6E53023/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1642145256556.png" alt="PavelK_0-1642145256556.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, could you please tell me what PAN-OS you are running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 07:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/458709#M101930</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-14T07:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: VWire Radius (NPS) via Mgmt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/458716#M101931</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/183065"&gt;@annielee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That really looks like an issue with the management interface and the HA setup, the daemon is trying to allocate the IP to make the request from to the socket but cannot, the only thing I can think is that when you do the test authentication it is actually sourced from the local box you are on at the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could check at the RADIUS end to see which IP is being presented as the client when the test succeeds, if that is the case it could well be an issue with floating IP allocation for the Active/Active HA to communicate to the RADIUS server, I am not really used to Active Active deployments but thought I would suggest that anyway.&lt;/P&gt;&lt;P&gt;Hope you get it worked out!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 08:49:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vwire-radius-nps-via-mgmt/m-p/458716#M101931</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2022-01-14T08:49:29Z</dc:date>
    </item>
  </channel>
</rss>

