<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius access for MGT conflict radius for user access. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-access-for-mgt-conflict-radius-for-user-access/m-p/40477#M29720</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use radius profiles for internal users towards a customer internal network policy server and so. The administration of the palo firewall is done via the MGT interface on a dedicted pvlan based administration network. We want to enable radius authentication for administrator purposes , but this seems to be impossible due to the fact that the service routing for radius&amp;nbsp; (the interface selected is is the L3 interface of the customer zone ) is occupied. The radius requests for the MGT is also send via this way, wrong off course, it should come via the administration network towards another ( cisco ACS) server. Can this be done ? Seems it is impossible to make sure the MGT uses the MGT network interface apart from the customer zones.&lt;/P&gt;&lt;P&gt;Specific routings towards the ACS system in this service config pages seem to work, but the source ipaddress from the request is not the one from the MGT interface but from a L3 interface on the fw. speificied for the customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be solved somehow ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Dec 2012 13:15:15 GMT</pubDate>
    <dc:creator>gejack</dc:creator>
    <dc:date>2012-12-12T13:15:15Z</dc:date>
    <item>
      <title>Radius access for MGT conflict radius for user access.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-access-for-mgt-conflict-radius-for-user-access/m-p/40477#M29720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use radius profiles for internal users towards a customer internal network policy server and so. The administration of the palo firewall is done via the MGT interface on a dedicted pvlan based administration network. We want to enable radius authentication for administrator purposes , but this seems to be impossible due to the fact that the service routing for radius&amp;nbsp; (the interface selected is is the L3 interface of the customer zone ) is occupied. The radius requests for the MGT is also send via this way, wrong off course, it should come via the administration network towards another ( cisco ACS) server. Can this be done ? Seems it is impossible to make sure the MGT uses the MGT network interface apart from the customer zones.&lt;/P&gt;&lt;P&gt;Specific routings towards the ACS system in this service config pages seem to work, but the source ipaddress from the request is not the one from the MGT interface but from a L3 interface on the fw. speificied for the customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this be solved somehow ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 13:15:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-access-for-mgt-conflict-radius-for-user-access/m-p/40477#M29720</guid>
      <dc:creator>gejack</dc:creator>
      <dc:date>2012-12-12T13:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius access for MGT conflict radius for user access.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-access-for-mgt-conflict-radius-for-user-access/m-p/40478#M29721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You can try this.&amp;nbsp; Define 2 Radius servers/profiles, 1 for users and 1 for admin, where each server has a difference IP address.&amp;nbsp; Then point the service route to 1 Radius server using mgt port, and use the destination option on the right to source from the 2nd interface to the 2nd Radius server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2012 15:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-access-for-mgt-conflict-radius-for-user-access/m-p/40478#M29721</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-12-12T15:47:41Z</dc:date>
    </item>
  </channel>
</rss>

