<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect portal user authentication failed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238961#M68450</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21822"&gt;@howardtopher&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To know if you are hitting a known bug, we would need to know your PAN-OS version and GP agent version &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recall this issue a while ago this issue was brought up and the fix was modifying the retries and timout values lower; something with that agent version was timing out the authentication on the agent side of things before getting a response. That particular issue if I recall correctly had much higher values in both fields however.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2018 20:32:35 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-11-07T20:32:35Z</dc:date>
    <item>
      <title>GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238931#M68444</link>
      <description>&lt;P&gt;For globalprotect I have a radius&amp;nbsp;server profile with two servers in it.&amp;nbsp; I have noticed that all authentication goes to the first server in the list all the time.&amp;nbsp; And that works.&amp;nbsp; However, in testing, I have shut off the first server and the firewall never tries to send authentcation to the second server.&amp;nbsp; If I use the "test authentication" command on the firewall CLI, it does fail over to the second server and authentication succeeds.&amp;nbsp; If I go back to the globalprotect client and try again, the firewall only tries the first server and authentication fails.&amp;nbsp; I have verified this with packet captures on the actual radius servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to be incorrect behavior.&amp;nbsp; Is it possible that there is a known bug about this?&amp;nbsp; I'm using the same authentication profile in the globalprotect portal configuration as I am on the test CLI command.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 18:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238931#M68444</guid>
      <dc:creator>howardtopher</dc:creator>
      <dc:date>2018-11-07T18:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238961#M68450</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21822"&gt;@howardtopher&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;To know if you are hitting a known bug, we would need to know your PAN-OS version and GP agent version &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recall this issue a while ago this issue was brought up and the fix was modifying the retries and timout values lower; something with that agent version was timing out the authentication on the agent side of things before getting a response. That particular issue if I recall correctly had much higher values in both fields however.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238961#M68450</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-07T20:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238968#M68452</link>
      <description>&lt;P&gt;Our PAN-OS is 8.0.10.&amp;nbsp; Maintenance night is next Friday, we'll jump to 8.0.13&amp;nbsp;at that point&amp;nbsp;unless 8.0.14 gets released before then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Globalprotect is 4.1.5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried setting the timeout to 1 second and retries to 1 in the server profile, but that didn't make a difference.&amp;nbsp; The globalprotect client says "connecting..." for a good 30 seconds before giving up (I haven't timed it, but it's feels long).&amp;nbsp; The CLI fails over to the second server in the 1 second timeout that's configured.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238968#M68452</guid>
      <dc:creator>howardtopher</dc:creator>
      <dc:date>2018-11-07T20:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238982#M68454</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21822"&gt;@howardtopher&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't think it's your PAN-OS version, nothing in the release notes point towards a fix for anything to do with RADIUS between those versions. You could be running into GPC-7215 if you are using SSO.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 21:01:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/238982#M68454</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-07T21:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/239080#M68477</link>
      <description>&lt;P&gt;yes &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;i remember that post too!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;unfortunately the poster never updated so still hanging...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the main pont to remember is that the max retries is 5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if you have&amp;nbsp;2 servers then only set retries to&amp;nbsp;3. (or less)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have just tested 4.15, i have radius server profile with 2 laptops running wireshark.&lt;/P&gt;&lt;P&gt;the timeout is 3 and retries is 3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i see the first laptop get 3 radius requests with about a 3 to 3.5 second interval.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i then see laptop 2 get 2 radius requests (total 5) with similar intervals.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as soon as the second one times out my GP client re prompts for username and password so all looking OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i cannot think why you would have such an issue...&amp;nbsp;&amp;nbsp; i have tested this on V7.1x and 8.08&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/239080#M68477</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-08T14:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect portal user authentication failed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/239081#M68478</link>
      <description>&lt;P&gt;Ye olde poste...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Radius-authentication-for-Global-Protect/td-p/226447" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Radius-authentication-for-Global-Protect/td-p/226447&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-user-authentication-failed/m-p/239081#M68478</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-08T14:59:54Z</dc:date>
    </item>
  </channel>
</rss>

