<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Admin authentication using RADIUS without local accounts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18058#M13163</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran across a strange issue when provisioning a new Administrator on our team. The background is that we use Cisco ACS 5.1 as our RADIUS authentication for our PA firewalls. All of the correct VSAs are input and appropriate Authorization Policies created for Firewalls and Panorama. We do not use local accounts, and instead rely on ACS to do authorization, which keeps things centralized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I noticed that after I had provisioned this new admin account on ACS the user was not able to successfully authenticate via SSH to the PA firewall. After quite a bit of testing and troubleshooting I ultimately determined that if you do not first authenticate to the firewall via Web UI, you cannot authenticate via SSH. Very odd I thought.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone else can attempt to replicate this issue, please let me know. It's a simple enough work around so nothing critical but I found it curious. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Affected verisons I could test:&lt;/P&gt;&lt;P&gt;3.1.5&lt;/P&gt;&lt;P&gt;4.0.1&lt;/P&gt;&lt;P&gt;4.0.7&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jan 2012 19:25:09 GMT</pubDate>
    <dc:creator>lwheelock</dc:creator>
    <dc:date>2012-01-25T19:25:09Z</dc:date>
    <item>
      <title>Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18058#M13163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran across a strange issue when provisioning a new Administrator on our team. The background is that we use Cisco ACS 5.1 as our RADIUS authentication for our PA firewalls. All of the correct VSAs are input and appropriate Authorization Policies created for Firewalls and Panorama. We do not use local accounts, and instead rely on ACS to do authorization, which keeps things centralized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I noticed that after I had provisioned this new admin account on ACS the user was not able to successfully authenticate via SSH to the PA firewall. After quite a bit of testing and troubleshooting I ultimately determined that if you do not first authenticate to the firewall via Web UI, you cannot authenticate via SSH. Very odd I thought.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone else can attempt to replicate this issue, please let me know. It's a simple enough work around so nothing critical but I found it curious. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Affected verisons I could test:&lt;/P&gt;&lt;P&gt;3.1.5&lt;/P&gt;&lt;P&gt;4.0.1&lt;/P&gt;&lt;P&gt;4.0.7&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 19:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18058#M13163</guid>
      <dc:creator>lwheelock</dc:creator>
      <dc:date>2012-01-25T19:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18059#M13164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the question..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would appear that this has been reported before.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a bug where "out-of-device" admin accounts require a webUI logon first before the SSH logon works. This is because when you configure admin user on PAN, it also creates a home directory for that user. If you have defined an admin on Radius only, then PAN does not have that user's corresponding home directory. In that case first-time login via SSH fails because there is no home directory. When you first login via webUI it will create that home directory for subsequent SSH logons. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The workaround for this is to configure admins on PAN itself via the Device-&amp;gt;Administrators tab for admins that would only have CLI access. At present, this bug has not resolved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might be fixed soon in a future release, but we do not know as of yet when that will be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are having issues where locally configured administrators are having to logon via the webUI first, then please call into PAN support for a live troubleshooting session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2012 22:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18059#M13164</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-25T22:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18060#M13165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;This issue has come up in 5.0.1, and is resolved in 5.0.5 and 5.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ref case 120090&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jul 2013 19:14:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18060#M13165</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2013-07-30T19:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18061#M13166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tested in 5.0.6 and it is still an issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 18:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18061#M13166</guid>
      <dc:creator>lwheelock</dc:creator>
      <dc:date>2013-08-05T18:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18062#M13167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update.. Please allow me to clarify.. &lt;/P&gt;&lt;P&gt;on your FW device, you have an admin role as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; test2-admin-role {&lt;/P&gt;&lt;P&gt;&amp;nbsp; role {&lt;/P&gt;&lt;P&gt;&amp;nbsp; device {&lt;/P&gt;&lt;P&gt;&amp;nbsp; cli superreader;&lt;/P&gt;&lt;P&gt;&amp;nbsp; webui {&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;??&lt;/P&gt;&lt;P&gt;Or you need Panorama to push down an admin role also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please confirm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 19:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18062#M13167</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2013-08-05T19:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18063#M13168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No such admin role. Admin role is sent via VSA in RADIUS accept message. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 20:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18063#M13168</guid>
      <dc:creator>lwheelock</dc:creator>
      <dc:date>2013-08-05T20:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18064#M13169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a bug 32363 which has been previously reported. However the bug will be fixed in next Major release. So it is not in 5.0.x.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 06:35:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18064#M13169</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-06T06:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Admin authentication using RADIUS without local accounts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18065#M13170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See also: bug ID &lt;SPAN class="tabs2_section_1 tabs2_section"&gt;&lt;SPAN style="margin-bottom: 5px;"&gt;&lt;SPAN&gt;&lt;SPAN class="activity_update_group"&gt;59031&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; / &lt;SPAN class="tabs2_section_1 tabs2_section"&gt;&lt;SPAN style="margin-bottom: 5px;"&gt;&lt;SPAN&gt;&lt;SPAN class="activity_update_group"&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="6773" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-6773"&gt;https://live.paloaltonetworks.com/docs/DOC-6773&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jul 2014 20:43:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/admin-authentication-using-radius-without-local-accounts/m-p/18065#M13170</guid>
      <dc:creator>JohnPetrucci</dc:creator>
      <dc:date>2014-07-14T20:43:18Z</dc:date>
    </item>
  </channel>
</rss>

