<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius authentication not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528869#M109191</link>
    <description>&lt;P&gt;If this traffic traverses firewall you can check Monitor &amp;gt; Logs &amp;gt; Traffic if those sessions are permitted, and if packets are sent and received.&lt;/P&gt;
&lt;P&gt;You can also take packet capture&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/take-packet-captures/take-a-packet-capture-on-the-management-interface" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/take-packet-captures/take-a-packet-capture-on-the-management-interface&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 13:27:28 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2023-01-27T13:27:28Z</dc:date>
    <item>
      <title>Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528852#M109187</link>
      <description>&lt;P&gt;We have configured Radius on our VM Palo but its not working. Provided screenshots of configuration we have on the FW and output of test command. Routing is defiantly in place as we can ping Radius server, however no traffic on 1812 reaching PacketFence Radius server. When done tcp dump - I can clearly see it's capturing pings but nothing for port 1812.&lt;/P&gt;
&lt;P&gt;Palo Support not being helpful as for now just keep sending me unrelated articles... So hopefully get some advice here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Target vsys is not specified, user '*******' is assumed to be configured with a shared auth profile.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Egress: x.x.208.14&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Authentication to RADIUS server at x.x.65.40:1812 for user '*******'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Authentication type: PAP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Now send request to remote server ...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;RADIUS error: bind: Cannot assign requested address&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Authentication failed against RADIUS server at x.x.65.40:1812 for user '*********'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;SPAN class=""&gt;Authentication failed for user '****'&lt;/SPAN&gt;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Fri, 27 Jan 2023 11:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528852#M109187</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T11:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528867#M109189</link>
      <description>&lt;P&gt;Monitor &amp;gt; Logs &amp;gt; System&lt;/P&gt;
&lt;P&gt;Filter:&amp;nbsp;( subtype eq auth )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see auth attempts in logs? What is in log description?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default traffic sourced from Palo goes out from mgmt interface.&lt;/P&gt;
&lt;P&gt;Assuming radius server IP is 1.2.3.4 does command "ping host 1.2.3.4" get replies?&lt;/P&gt;
&lt;P&gt;Is Palo mgmt interface and radius server in same subnet or does this traffic traverse firewall?&lt;/P&gt;
&lt;P&gt;If it traverses firewall do you see those sessions in traffic log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:14:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528867#M109189</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T13:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528868#M109190</link>
      <description>&lt;P&gt;ping is going through to radius - I have even add "source" in command to be sure is coming out of management interface.&lt;/P&gt;
&lt;P&gt;We can see Auth logs as well but obviously not succesfull :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;( description contains 'failed authentication for user \'*****\'. Reason: Authentication request is timed out. auth profile \'PF-Radius\', vsys \'shared\', server profile \'PF-Radius\', server address \'x.x.65.40\', auth protocol \'PAP\', From: x.x.x.x' )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528868#M109190</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T13:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528869#M109191</link>
      <description>&lt;P&gt;If this traffic traverses firewall you can check Monitor &amp;gt; Logs &amp;gt; Traffic if those sessions are permitted, and if packets are sent and received.&lt;/P&gt;
&lt;P&gt;You can also take packet capture&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/take-packet-captures/take-a-packet-capture-on-the-management-interface" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/monitoring/take-packet-captures/take-a-packet-capture-on-the-management-interface&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528869#M109191</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T13:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528870#M109192</link>
      <description>&lt;P&gt;Yep, we have checked monitor and no intersting traffic was there. Will try to setup capture to see it there. Just wondering if tcp dump from command line is sufficient an that was already done - we could see ping to radius server but nothing on 1812.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528870#M109192</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T13:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528871#M109193</link>
      <description>&lt;P&gt;All services (including radius) are configured to use default (mgmt interface)?&lt;/P&gt;
&lt;P&gt;Device &amp;gt; Setup &amp;gt; Services &amp;gt;&amp;nbsp;Service Route Configuration&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528871#M109193</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T13:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528877#M109195</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/212982"&gt;@T_Wojtasinski&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "&lt;SPAN class=""&gt;RADIUS error: bind: Cannot assign requested address&lt;/SPAN&gt;" is your issue.&amp;nbsp; I have not seen that one, and it is difficult to interpret.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From your posts, it sounds like the network is fine, and the NGFW is not blocking the traffic.&amp;nbsp; You may want to try these steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What RADIUS server are you using?&lt;/LI&gt;
&lt;LI&gt;Have you configured the management IP of the NGFW as a client on your RADIUS server?&lt;/LI&gt;
&lt;LI&gt;Have you verified the shared secret?&lt;/LI&gt;
&lt;LI&gt;Have you checked the logs on the RADIUS server?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once done, please test with the "test authentication authentication-profile" CLI command.&amp;nbsp; It gives very specific errors if it fails.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:02:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528877#M109195</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-27T14:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528880#M109197</link>
      <description>&lt;P&gt;Good catch&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;about&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;RADIUS error: bind: Cannot assign requested address&lt;/SPAN&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Device &amp;gt; Setup &amp;gt; Services &amp;gt;&amp;nbsp;Service Route Configuration is set to default to use mgmt interface?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Management interface is up and connected?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:10:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528880#M109197</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T14:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528881#M109198</link>
      <description>&lt;P&gt;Thanks for coming back - I think it might be the case. As this setup was done before my time - did not check that.&lt;/P&gt;
&lt;P&gt;Looks like there is a some misconfig(attached screenshots)&amp;nbsp; - in IPV4 section - there is a wrong IP (other FW) but I'm not able to change this IP. In "destination" new Radius IP(x.x.65.40) was missing so I've aded it(x.x.209.15 but I think it should be x.x.209.14 without specifying interface) - but still no luck.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now I found another issue - mgmt IP of the FW is x.x.209.14 but mgmt interface is configured with&amp;nbsp;x.x.209.15.&lt;/P&gt;
&lt;P&gt;So to log to the box we're using .15 but mgmt traffic is .14 - that might be "source" of all troubles.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528881#M109198</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T14:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528882#M109199</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's a PacketFence Radius in AWS and all configuration there in place(we could see ping from Palo on this server).&lt;/P&gt;
&lt;P&gt;Secret is ok as well. We have done tcp dump so we could see ping response from the PF Radius but no 1812 as it was not reaching there. Output from "test" command is in original post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As this VM Palo was configured before my time in this company - I found "couple" of issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="bodyDisplay_3" class=""&gt;
&lt;DIV class=""&gt;
&lt;P&gt;mgmt IP of the FW is x.x.209.14 but mgmt interface is configured with&amp;nbsp;x.x.209.15.&lt;/P&gt;
&lt;P&gt;So to log to the box we're using .15 but mgmt traffic is .14 - that might be "source" of all troubles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also looks like there is a misconfig with service routes for Radius - its not allowing me to change existing IP's/setup(I'm "Superuser")&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528882#M109199</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T14:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528884#M109201</link>
      <description>&lt;P&gt;yeah, I think these double IP management setup causing issue...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its a VM Palo in AWS so not sure whether I should change mgmt to .15 - same as interface or change IP on interface to .14 - mgmt IP address (both screen attached) - and if reboot of FW or instance required.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528884#M109201</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T14:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528885#M109202</link>
      <description>&lt;P&gt;Mgmt interface IP and dataplane interface IP can't be the same so you need to keep them different.&lt;/P&gt;
&lt;P&gt;Your issue is in service routes.&lt;/P&gt;
&lt;P&gt;Take screenshot of current status.&lt;BR /&gt;Set all to default and click OK (do not commit).&lt;/P&gt;
&lt;P&gt;Go back and set according to your need and then commit.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:52:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528885#M109202</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T14:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528886#M109203</link>
      <description>&lt;P&gt;I've just added screenshots with current setup (2 newest). Unfortunately even with bringing it to default , when trying to reconfigure - it's bringing up wrong 208.14 IP. If I put mgmt interface IP - it will accept as its autofilling but whatever I type in box- its not accepting it - just coming with wrong .208.14 or other preconfigured staff&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528886#M109203</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T15:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528888#M109204</link>
      <description>&lt;P&gt;If you don't choose source interface then it is normal that it comes up with .14 because your firewall mgmt interface is configured with .14.&lt;/P&gt;
&lt;P&gt;Your second screenshot shows that you have chosen ethernet1/2 as source and IP as .15&lt;/P&gt;
&lt;P&gt;So what is still the problem?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:11:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528888#M109204</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T15:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528889#M109205</link>
      <description>&lt;P&gt;The IP in first section is wrong - someone put x.x.208.14 whereas this FW is x.x.209.14 mgmt IP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question is if I should use mgmt IP here or mgmt interface with .209.15?&lt;/P&gt;
&lt;P&gt;In service route should I put source interface with x.x.209.15 ? Radius server expecting traffic from mgmt IP - x.x.209.14(or its irrelevant)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528889#M109205</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T15:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528891#M109206</link>
      <description>&lt;P&gt;Your Palo mgmt interface gets 209 IP from DHCP. It is not manually configured on Palo.&lt;/P&gt;
&lt;P&gt;Seems you need to use ethernet1/2 as source interface and .15 IP to get all working. Unless you review and change underlying virtual networking setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1674833612086.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47473iC07C2384CFF78F95/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1674833612086.png" alt="Raido_Rattameister_0-1674833612086.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528891#M109206</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T15:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528897#M109207</link>
      <description>&lt;P&gt;I have changed in Service Route config IPV4 and Destination IP to x.x.209.15 with src int 1/2.&lt;/P&gt;
&lt;P&gt;I think it did some "trick" as now when applying "test"command on cli I dont have any errors - its just hanging with out any output.&lt;/P&gt;
&lt;P&gt;Also I can see traffic logs(attached) with reason for session end "n/a"&lt;/P&gt;
&lt;P&gt;So hopefully changing IP on PF RAdious to .209.15 (as its setup for .14) will do the trick.&lt;/P&gt;
&lt;P&gt;Or should we look int changing mgmt IP in DHCP to .15 as well?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 16:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528897#M109207</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T16:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528900#M109209</link>
      <description>&lt;P&gt;As mentioned earlier ethernet1/2 and mgmt can't have same .15 IP.&lt;/P&gt;
&lt;P&gt;If you look at VM config then first nic is mgmt port on Palo, second nic ethernet1/1, third nic ethernet1/2 etc.&lt;/P&gt;
&lt;P&gt;So vNic config that matches mgmt port in Palo is in different virtual network/zone compared to ethernet1/2 one.&lt;/P&gt;
&lt;P&gt;That is why you get different IP from DHCP.&lt;/P&gt;
&lt;P&gt;So you need to engage your network persons if you want to use mgmt port for radius.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 16:18:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528900#M109209</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-01-27T16:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528901#M109210</link>
      <description>&lt;P&gt;Ok, understand it now - just bit new to VM solution in AWS - last good few years was working with multiple physical Palo boxes.&lt;/P&gt;
&lt;P&gt;Will check with Radius guys to change IP to .15 there and hopefully it will work with&amp;nbsp; Radius request coming from eth 1/2 with x.x.209.15 IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again for your help - much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 16:16:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-not-working/m-p/528901#M109210</guid>
      <dc:creator>T_Wojtasinski</dc:creator>
      <dc:date>2023-01-27T16:16:51Z</dc:date>
    </item>
  </channel>
</rss>

