<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL VPN and RADIUS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14119#M10371</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anybody have a walk through on setting this up.&amp;nbsp; I have SSL VPN enabled currently on our PA2050 for a few folks however I'm using the local database for it and would like to switch to RADIUS authentication.&amp;nbsp; I don't currently have a RADIUS server however I was just thinking of using the built in stuff with Win Server 2003 unless someone could recommend something better.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Oct 2010 13:16:25 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2010-10-22T13:16:25Z</dc:date>
    <item>
      <title>SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14119#M10371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anybody have a walk through on setting this up.&amp;nbsp; I have SSL VPN enabled currently on our PA2050 for a few folks however I'm using the local database for it and would like to switch to RADIUS authentication.&amp;nbsp; I don't currently have a RADIUS server however I was just thinking of using the built in stuff with Win Server 2003 unless someone could recommend something better.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 13:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14119#M10371</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-10-22T13:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14120#M10372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to create a RADIUS profile and then an Authentication Profile that uses the RADIUS Profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===========================================&lt;/P&gt;&lt;P&gt;Device Tab.&lt;BR /&gt;Server Profiles &amp;gt;&amp;gt; RADIUS&lt;BR /&gt;Click "NEW"&lt;BR /&gt;- Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (ASCII text)&lt;BR /&gt;- Timeout&amp;nbsp; (1-30 Secs)&lt;BR /&gt;- Retries&amp;nbsp;&amp;nbsp; (1-5)&lt;/P&gt;&lt;P&gt;Servers: (Max of 4)&lt;BR /&gt;- Name&lt;BR /&gt;- IP ADDR&lt;BR /&gt;- Port (Usually 1812)&lt;BR /&gt;- Secret&lt;BR /&gt;- Secret confirmed&lt;BR /&gt;==========================================&lt;BR /&gt;Device Tab:&lt;BR /&gt;Authentication Profile&lt;BR /&gt;Click "NEW"&lt;/P&gt;&lt;P&gt;Profile Name: (ASCII Text)&lt;BR /&gt;Lockout Section:&lt;BR /&gt;- Failed Attempts&amp;nbsp; (0-10)&lt;BR /&gt;- Lockout Time:&amp;nbsp;&amp;nbsp;&amp;nbsp; (0-60 Min)&lt;/P&gt;&lt;P&gt;Allow List Section:&lt;BR /&gt;- Click "Edit Allow List"&lt;BR /&gt;- Additional users: type "all"&lt;BR /&gt;- Click OK&lt;BR /&gt;===========================================&lt;/P&gt;&lt;P&gt;Now you can use your Authentication profile for RADIUS instead of an Auth Profile for local DB.&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Oct 2010 18:08:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14120#M10372</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2010-10-22T18:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14121#M10373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I know this isn't a Palo Alto probem but I've got all this setup now however I can't get the PA box to talk to my RADIUS server.&amp;nbsp; Working through that at the moment.&amp;nbsp; I do have an additional question, I can see us using this feature more heavily in the future.&amp;nbsp; Is there a way to cap the bandwidth that a SSL VPN session uses?&amp;nbsp; Am I getting beyond what this device can do, should I start looking at a dedicated appliance (Juniper or Checkpoint perhaps?)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 17:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14121#M10373</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-10-25T17:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14122#M10374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we can QOS the ssl-vpn traffic, as it is based on the egress zone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 01:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14122#M10374</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2010-10-27T01:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14123#M10375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, so RADIUS isn't working out that well for me.&amp;nbsp; Is there a way to have the SSL VPN sessions authenticate through Active Directory?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, would you be able to elaborate more on what your referencing with setting up QoS for this traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 15:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14123#M10375</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-10-27T15:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14124#M10376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The key is to determine if radius server is communicating with PAN when user attempts to authenticate.&lt;/P&gt;&lt;P&gt;Regarding QOS&lt;/P&gt;&lt;P&gt;This doc should walk thru configuring and testing qos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1162"&gt;https://live.paloaltonetworks.com/docs/DOC-1162&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you require more information please open a case with support to walk thru your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gary S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 02:05:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-radius/m-p/14124#M10376</guid>
      <dc:creator>gsamuels</dc:creator>
      <dc:date>2010-10-28T02:05:31Z</dc:date>
    </item>
  </channel>
</rss>

