<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with WLC Radius request to NPS Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/251150#M71416</link>
    <description>&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Arial, Helvetica; font-size: 13.333333015441895px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;PAN-93609&lt;/SPAN&gt; is when an initial packet arrives that is fragmented it could be dropped, usually but not limited to udp (this was fixed in 8.0.11)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it might be worth looking into upgrading&lt;/P&gt;
&lt;P&gt;the currently recommended release in your code train is 8.0.15&lt;/P&gt;</description>
    <pubDate>Mon, 25 Feb 2019 12:19:14 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2019-02-25T12:19:14Z</dc:date>
    <item>
      <title>Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250876#M71340</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have an issue with the radius request through the firewall,&lt;/P&gt;&lt;P&gt;The radius request come from an cisco 1852-ME WLC and goes to an Windows 2016 NPS Server, both in different zones.&lt;/P&gt;&lt;P&gt;An simular setup with an firewall works fine.&lt;/P&gt;&lt;P&gt;The NPS Server does not react on the requests. With Wireshark I can see the request and Answer from the NPS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect that the Certificate (used for auth) have changed at the firewall.&lt;/P&gt;&lt;P&gt;AFAIK certificate inspection is disabled (where I can check this?)&lt;/P&gt;&lt;P&gt;Does somebody else has an simular setup? What do I have to check for?&lt;/P&gt;&lt;P&gt;As I'm new on Palo, I could have missed something here.&lt;/P&gt;&lt;P&gt;Thanks for your feedback&amp;nbsp;&lt;/P&gt;&lt;P&gt;Willem&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 12:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250876#M71340</guid>
      <dc:creator>willem.degroot</dc:creator>
      <dc:date>2019-02-22T12:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250893#M71345</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107381"&gt;@willem.degroot&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can see which TLS Interception Policy is defined by looking at Policy &amp;gt; Decryption Policy.&lt;/P&gt;&lt;P&gt;If there is a policy which does SSL Forward Proxy (MitM), then certificates are exchanged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But: Radius runs with UDP, so there is no TLS support - I guess the problem is somewhere else.&lt;/P&gt;&lt;P&gt;Do you see the request in the NPS log?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 13:12:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250893#M71345</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-02-22T13:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250899#M71347</link>
      <description>&lt;P&gt;Hi Willem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unless your implementation uses radius over ssl, the certificates should not be touched by the firewall&lt;/P&gt;
&lt;P&gt;ssl &lt;EM&gt;decryption&lt;/EM&gt; policies can be found under the policies tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can set up packetcapture on the firewall as well and set it so you capture ingres and egress, that way you can compare what goes into and what comes out&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can match your captures to global counters, to verify if anything additional of interest pops up:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://paloaltonetworks.my.salesforce.com/kA10g000000ClTJ?srPos=0&amp;amp;srKp=ka1&amp;amp;lang=en_US" target="_blank"&gt;https://paloaltonetworks.my.salesforce.com/kA10g000000ClTJ?srPos=0&amp;amp;srKp=ka1&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'd probably look at NAT, routing and possibly timestamps on the radius/certificates&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 13:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250899#M71347</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-02-22T13:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250908#M71350</link>
      <description>&lt;P&gt;Hi Chacko42&lt;/P&gt;&lt;P&gt;Thanks for your reply. I agree on the UDP traffic.&lt;/P&gt;&lt;P&gt;In the Eventviewer there is no message BUT in the file found here&amp;nbsp;C:\Windows\System32\LogFiles There are messages like:&lt;/P&gt;&lt;PRE&gt;"EEMDC10","IAS",02/22/2019,14:44:01,1,"host/CHW7X576.sscgr.contoso.com","sscgr.contoso.com/chgr/zgi/Group_IT/resources/CHW7X576","b0-8b-cf-dc-e8-c0:V2ZDEWBC","88-b1-11-80-a8-b8",,,"CHGR-PAF-Office","172.16.129.20",1,0,"172.16.129.20","Test-AP-CHGR",,,19,,,2,5,"WLAN Office",0,"311 1 172.29.24.10 02/22/2019 10:25:00 514",,,,,,,,,"5c6fee90/88:b1:11:80:a8:b8/30",,,,,,,,,,,,,,,,,,,,,,,,,"Use Windows authentication for all users",1,,,,


"EEMDC10","IAS",02/22/2019,14:44:01,11,,"sscgr.contoso.com/chgr/zgi/Group_IT/resources/CHW7X576",,,,,,,,0,"172.16.129.20","Test-AP-CHGR",,,,,,,5,"WLAN Office",0,"311 1 172.29.24.10 02/22/2019 10:25:00 514",30,,,,,,,,"5c6fee90/88:b1:11:80:a8:b8/30",,,,,,,,,,,,,,,,,,,,,,,,,"Use Windows authentication for all users",1,,,,&lt;/PRE&gt;&lt;P&gt;I can also do a test from the WLC to the NPS with user credentials, this is working fine.&lt;/P&gt;&lt;P&gt;I'll keep on trying &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 14:03:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250908#M71350</guid>
      <dc:creator>willem.degroot</dc:creator>
      <dc:date>2019-02-22T14:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250909#M71351</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try the packet capture, to see what happens.&lt;/P&gt;&lt;P&gt;NAT and routing can be ignored.&lt;/P&gt;&lt;P&gt;Both ZONEs are internals without NAT&lt;/P&gt;&lt;P&gt;An test from the WLC to the NPS with user-credentials will be answered correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 14:07:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250909#M71351</guid>
      <dc:creator>willem.degroot</dc:creator>
      <dc:date>2019-02-22T14:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250922#M71354</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;I just could sniff and found an interesting difference between Firewall RX and TX.&lt;/P&gt;&lt;P&gt;Besides that I have duplicates in the trace, I see the following:&lt;/P&gt;&lt;P&gt;on the outgoing interface, there are packages missing, packages that are on the incomming interface with MTU of 1514, are not sendout the outgoing interface anymore.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Where do I have to check the Firewall settigns for this?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Incomming:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22-02-_2019_16-19-42.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18827i4AC85AC26A7D5C85/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="22-02-_2019_16-19-42.png" alt="22-02-_2019_16-19-42.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outgoing, note that request/response ID 5 is missing.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="22-02-_2019_16-20-35.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18830i92EC1FE6E34CA7B3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="22-02-_2019_16-20-35.png" alt="22-02-_2019_16-20-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 15:25:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250922#M71354</guid>
      <dc:creator>willem.degroot</dc:creator>
      <dc:date>2019-02-22T15:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250923#M71355</link>
      <description>Interesting&lt;BR /&gt;Are all your interfaces set to "normal" MTU? It may be worth looking into enabling jumbo frames and increasing the mtu on internal interfaces</description>
      <pubDate>Fri, 22 Feb 2019 15:32:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250923#M71355</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-02-22T15:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250950#M71363</link>
      <description>&lt;P&gt;After changing the radius configuration to use certificate based authentication - do you see eventlogs with the mmc &amp;gt; event manager? I assume it's a config thing on the nps server - there should be event ids for the requests - if there aren't, it has to do something with the network/firewall&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/250950#M71363</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-02-22T16:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/251147#M71413</link>
      <description>&lt;P&gt;Hi Reaper,&lt;/P&gt;&lt;P&gt;I increased the MTU on the (sub) Interfaces but without an positiv result.&lt;/P&gt;&lt;P&gt;I don't think that this will solve the issue anyway because I see in the Capture that the packet is Fragmented ( I try to capture nearer to the source.&lt;BR /&gt;What I have found is an Issue ID PAN-93609 but I do not have the right (yet) to access the reports.&lt;BR /&gt;May this be the issue?&lt;/P&gt;&lt;P&gt;I'm running PAN-OS 8.0.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 10:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/251147#M71413</guid>
      <dc:creator>willem.degroot</dc:creator>
      <dc:date>2019-02-25T10:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with WLC Radius request to NPS Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/251150#M71416</link>
      <description>&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Arial, Helvetica; font-size: 13.333333015441895px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;PAN-93609&lt;/SPAN&gt; is when an initial packet arrives that is fragmented it could be dropped, usually but not limited to udp (this was fixed in 8.0.11)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it might be worth looking into upgrading&lt;/P&gt;
&lt;P&gt;the currently recommended release in your code train is 8.0.15&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 12:19:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-with-wlc-radius-request-to-nps-server/m-p/251150#M71416</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-02-25T12:19:14Z</dc:date>
    </item>
  </channel>
</rss>

