<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius authentication for Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226447#M65193</link>
    <description>&lt;P&gt;Hi community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have encountered a "problem" with our Global Protect authentication while we were doing some maintenance works.&lt;/P&gt;&lt;P&gt;We have an Authentication Profile with 3 RADIUS servers for authenticating the users, and the number of retries is set to 5.&lt;/P&gt;&lt;P&gt;So, according to Palo Alto documentation, after 5 authentication attempts against server 1, it should try with server 2, and so on and so forth.&lt;/P&gt;&lt;P&gt;However, Global Protect client gives back the authentication fail after the 3rd attempt, so it will never try the server 2. We were doing maintenance on server 1 relying on the other 2 servers, but Global Protect was never using the other 2.&lt;/P&gt;&lt;P&gt;Is there any best practise to use here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 08 Aug 2018 14:18:26 GMT</pubDate>
    <dc:creator>Gabriel_Linero</dc:creator>
    <dc:date>2018-08-08T14:18:26Z</dc:date>
    <item>
      <title>Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226447#M65193</link>
      <description>&lt;P&gt;Hi community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have encountered a "problem" with our Global Protect authentication while we were doing some maintenance works.&lt;/P&gt;&lt;P&gt;We have an Authentication Profile with 3 RADIUS servers for authenticating the users, and the number of retries is set to 5.&lt;/P&gt;&lt;P&gt;So, according to Palo Alto documentation, after 5 authentication attempts against server 1, it should try with server 2, and so on and so forth.&lt;/P&gt;&lt;P&gt;However, Global Protect client gives back the authentication fail after the 3rd attempt, so it will never try the server 2. We were doing maintenance on server 1 relying on the other 2 servers, but Global Protect was never using the other 2.&lt;/P&gt;&lt;P&gt;Is there any best practise to use here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 14:18:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226447#M65193</guid>
      <dc:creator>Gabriel_Linero</dc:creator>
      <dc:date>2018-08-08T14:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226498#M65204</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73971"&gt;@Gabriel_Linero&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is auth failing at the GP Portal or the GP Gateway or both?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;Have you configured an auth sequence? Kind of sounds like you maybe haven't configured an authentication sequence.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 16:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226498#M65204</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-08T16:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226594#M65224</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, I haven't checked with the portal, but when you connect with the Global Protect client to the portal, it authenticates in both portal and gateway. We have the authentication override so we do only one authentication.&lt;/P&gt;&lt;P&gt;We don't have ideed authentication sequence, but as far as I know, that's for using different profile. What we have is one&amp;nbsp;authentication profile with one RADIUS server profile that inholds 3 RADIUS servers. As per Palo Alto documentation, when using the Server profile, it will try with the first server for the amount for retries, and then go to the second server.&lt;/P&gt;&lt;P&gt;We have configured 5 retires, but after the 3rd one (According to the logs) the client of Global Protect already go the authentication fail and asks the user to re-enter username and password.&lt;/P&gt;&lt;P&gt;We may need to configure less retries? Is Global Protect working in a different way when it retries the RADIUS authentication?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 11:01:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226594#M65224</guid>
      <dc:creator>Gabriel_Linero</dc:creator>
      <dc:date>2018-08-09T11:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226718#M65268</link>
      <description>&lt;P&gt;Hmmm...&amp;nbsp;&amp;nbsp; this is a bit confusing but...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the radius max retries is 5, as per documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if you set profile to 5 then it will try first server 5 times, it will not try server 2 because you have used up your 5 attempts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure about your logs but wireshark shows all attempts...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have 5 servers in the list then you must set retries to "1" or the last server will never get used..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so set retries to 2 or 3.&amp;nbsp; lets face it, if you do not hit your server after 2nd attempt then something is wrong....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can set auth sequence as per &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;. this will of course work but bear in mind that if a user enters an incorrect password or code then the same password/code will be used on server 2, so 2 bad auths registered against user... if you have 3 servers with a 3 attempts lockout policy then account locked on one attempt as it will try 3 times.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;starting to waffle on a bit... soz.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so....&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; have a max of 3 servers per profile and set it to 2 retries.&lt;/P&gt;&lt;P&gt;or 2 servers with retries of 3.&lt;/P&gt;&lt;P&gt;or 1 server with retries of 4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226718#M65268</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-08-10T12:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226721#M65270</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;, thanks a lot! will test that and see what happens &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 12:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226721#M65270</guid>
      <dc:creator>Gabriel_Linero</dc:creator>
      <dc:date>2018-08-10T12:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226723#M65272</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73971"&gt;@Gabriel_Linero&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I missed your update yesterday, but&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;is correct. The radius has a max retry value of 5; that doesn't mean that it will try all servers 5 times, it means it will attempt to auth the connection 5 times. It's slightly odd that you are only ever seeing 3 attempts, but if you have 3 servers you're retries should be set no greater then '2', noting that the 3rd radius server will only ever see 1 request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd also recommend simply verifying that if you remove 'Server 1' from the profile you'll actually able to authenticate via the other two servers. It's possible that configuration on the actual radius server itself isn't correct for the other two servers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:01:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226723#M65272</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-08-10T13:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226801#M65296</link>
      <description>Try doing packet capture for the radius traffic and check if the correct password is being sent for authentication. We have situation where the wrong password is being sent by the firewall or gp agent. It is adding # in front of the password. We have an open case with support on it</description>
      <pubDate>Sat, 11 Aug 2018 17:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226801#M65296</guid>
      <dc:creator>rj_raj</dc:creator>
      <dc:date>2018-08-11T17:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication for Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226802#M65297</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/65728"&gt;@rj_raj&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Could you share some more information about this issue:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PAN-OS version&lt;/LI&gt;&lt;LI&gt;GP-Agent version&lt;/LI&gt;&lt;LI&gt;Authentication (RADIUS, LDAP, ...)&lt;/LI&gt;&lt;LI&gt;Pre-Logon/On demand&lt;/LI&gt;&lt;LI&gt;Enforce Global Protect for network access enabled&lt;/LI&gt;&lt;LI&gt;...&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Maybe this would be helpful also for others here (and if others have the same problem and also open cases, this could also help you as the issue then gets a higher priority)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 18:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-for-global-protect/m-p/226802#M65297</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-11T18:16:25Z</dc:date>
    </item>
  </channel>
</rss>

