<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Invalid Role - RADIUS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63752#M38315</link>
    <description>&lt;P&gt;OK, next, did you check the box on your RADIUS profile "Administrator use only" (just underneath the profile name itself)?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2015 21:18:07 GMT</pubDate>
    <dc:creator>Lucky</dc:creator>
    <dc:date>2015-08-27T21:18:07Z</dc:date>
    <item>
      <title>Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63736#M38303</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am troubleshooting PA authentication using RADIUS. The user is part of the appropriate AD group for the RADIUS configuration and the PA and RADIUS server are both setup for RADIUS auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the PA side, added an administrator and set their auth profile as the radius profile. When the user tries to login, the PA log shows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User 'userX' authentication. From: IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then another message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authorization failed for user Userx via Web from IP : Invalid role&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 19:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63736#M38303</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2015-08-27T19:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63738#M38305</link>
      <description>&lt;P&gt;While I cannot remember the exact error we were seeing, however our usernames had a special character in the begining and the PAN did not like that at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if that is the case here.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 19:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63738#M38305</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-08-27T19:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63749#M38312</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when you added that new admin, can you check if you selected his/hers role as "dynamic" or "role based"? Could it be that you are missing role setup? Change that to dynamic just for test?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63749#M38312</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T21:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63751#M38314</link>
      <description>&lt;P&gt;Thank you for your reply. It's set to Dynamic - Superuser.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:15:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63751#M38314</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2015-08-27T21:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63752#M38315</link>
      <description>&lt;P&gt;OK, next, did you check the box on your RADIUS profile "Administrator use only" (just underneath the profile name itself)?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63752#M38315</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T21:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63753#M38316</link>
      <description>&lt;P&gt;and if you did, did you also try to uncheck it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:20:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63753#M38316</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T21:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63757#M38320</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;few more things that could be useful in troubleshooting:&lt;/P&gt;&lt;P&gt;less mp-log authd.log&lt;/P&gt;&lt;P&gt;tail follow yes mp-log authd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and if needed, big hammer:&lt;/P&gt;&lt;P&gt;debug authentication connection-show protocol-type &amp;lt;TACACS+|LDAP|Kerberos|RADIUS&amp;gt; connection-id &amp;lt;0-4294967295&amp;gt;&lt;BR /&gt;debug authentication connection-debug-on protocol-type &amp;lt;TACACS+|LDAP|Kerberos|RADIUS&amp;gt; connection-id &amp;lt;0-4294967295&amp;gt; debug-prefix &amp;lt;value&amp;gt;&lt;BR /&gt;debug authentication connection-debug-off protocol-type &amp;lt;TACACS+|LDAP|Kerberos|RADIUS&amp;gt; connection-id &amp;lt;0-4294967295&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;last, but not the least, a few articles...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;troubleshooting radius&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Articles/Troubleshooting-RADIUS-Authentication/ta-p/59200" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/Troubleshooting-RADIUS-Authentication/ta-p/59200&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;identify secret key mismatch for radius&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Articles/How-to-Identify-Secret-Key-Mismatch-Between-Palo-Alto-Networks/ta-p/54612" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/How-to-Identify-Secret-Key-Mismatch-Between-Palo-Alto-Networks/ta-p/54612&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin roles (in panorama but you can correlate):&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Articles/Separate-Panorama-Admins-Access-Domains-using-RADIUS/ta-p/54432" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/Separate-Panorama-Admins-Access-Domains-using-RADIUS/ta-p/54432&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 21:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/63757#M38320</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T21:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/535087#M110097</link>
      <description>&lt;P&gt;I am facing the exact same issue. Did you happen to resolve this? If so, could you please let me know the fix.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 15:02:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/535087#M110097</guid>
      <dc:creator>CharlesAntonyAlfred</dc:creator>
      <dc:date>2023-03-20T15:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Role - RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/549411#M112107</link>
      <description>&lt;P&gt;Same issue as well&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 19:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/invalid-role-radius/m-p/549411#M112107</guid>
      <dc:creator>Schneur_Feldman</dc:creator>
      <dc:date>2023-07-14T19:57:51Z</dc:date>
    </item>
  </channel>
</rss>

