<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Sequence not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/313159#M80888</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;- Security rule is set to Deny and not Drop or Reset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;- Yes, the documentations suggests lookup feature rather than failure.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2020 17:15:06 GMT</pubDate>
    <dc:creator>Sly_Cooper</dc:creator>
    <dc:date>2020-02-26T17:15:06Z</dc:date>
    <item>
      <title>Authentication Sequence not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/312895#M80852</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have successfully tested Authentication policy using LDAP, MFA (Okta API), SAML and RADIUS (Okta). I am working on the redundancy scenarios wherein if Okta fails, the fallback would be LDAP. I am using RADIUS (Okta) and LDAP in the Authentication Sequence. I am however unable to get the LDAP (Active Directory) fallback working. I am simulating RADIUS(OKTA) failure by configuring the service route to use the firewall traffic interface and then a security policy to block the RADIUS traffic. I can see that the firewall is successfully blocking RADIUS traffic. I however, want it to proceed to LDAP auth and authenticate considering RADIUS unavailability. I am using default-web-form in the auth policy and CP is set to use the authentication sequence. The authentication logs only show Authentication Failure with the RADIUS server events. What am I missing? Will this config ever work?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 20:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/312895#M80852</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2020-02-25T20:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sequence not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/312961#M80856</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/30703"&gt;@Sly_Cooper&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just to verify, your security rule is set to drop the traffic and not send a reset correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 03:37:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/312961#M80856</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-02-26T03:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sequence not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/313135#M80885</link>
      <description>&lt;P&gt;i dont think this works on a total failure of the first auth in the sequence, it only seems to work if the first auth returns a "no".&lt;/P&gt;&lt;P&gt;if no response at all then it just times out the entire sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the above happens to me on V8.14 GP portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't even think it was intended for use with multiple user accounts, it was more designed for a single user account on multiple auth servers with different passwords.&lt;/P&gt;&lt;P&gt;Having said that it still does not work for me if first auth server is down, or in your case... blocked!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 15:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/313135#M80885</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-02-26T15:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Sequence not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/313159#M80888</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;- Security rule is set to Deny and not Drop or Reset.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;- Yes, the documentations suggests lookup feature rather than failure.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 17:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-sequence-not-working/m-p/313159#M80888</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2020-02-26T17:15:06Z</dc:date>
    </item>
  </channel>
</rss>

