<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect multifactor authentication with RADIUS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multifactor-authentication-with-radius/m-p/324386#M82815</link>
    <description>&lt;P&gt;The PAN-OS version is 8.1.8 when I found the known issue:-&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;PAN-97757&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;BR /&gt;GlobalProtect authentication fails with an Invalid username/password error (because the user is not found in Allow List) after you enable GlobalProtect authentication cookies and add a RADIUS group to the Allow List of the authentication profile used to authenticate to GlobalProtect.&lt;BR /&gt;Workaround: Disable GlobalProtect authentication cookies. Alternatively, disable (clear) Retrieve user group from RADIUS in the authentication profile and configure group mapping from Active Directory (AD) through LDAP&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 22 Apr 2020 20:48:07 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2020-04-22T20:48:07Z</dc:date>
    <item>
      <title>Global protect multifactor authentication with RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multifactor-authentication-with-radius/m-p/324385#M82814</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured GP with multifactor authentication.&lt;/P&gt;&lt;P&gt;Example:- If I want to connect VPN, so I click to connect on agent it will prompt me to credential then I will enter username and password once it is succeded one OTP received my mobile. after entering the OTP. I can connect the VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Randomly I am facing issues some users not able to connect VPN if they enter credentials(5-6 times) the error occurs user name password is incorrect.&lt;/P&gt;&lt;P&gt;Workaround - I remove all the settings from the agent and enter the portal name after that I can able to log in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Highlight points:- When I did the troubleshooting:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I can see the error - &amp;nbsp; (Auth FAILED for user "ABC" thru &amp;lt;"MFA-VPN", "vsys1"&amp;gt;: remote server 10.20.182.42 of server profile "MFA-VPN-Radius" is down, or in retry interval, or request timed out (elapsed time 25 secs, max allowed 25 secs)&lt;/P&gt;&lt;P&gt;For this error, I went through some KB and found I need to increase the Global protect timeout.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNmaCAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNmaCAG&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) When I test the authentication profile get the error -&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "ABC" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication requests...&lt;/P&gt;&lt;P&gt;For this:- I can able to ping the RADIUS server and some users test authentication succeded and for the ABC user test is succeed sometimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) In the portal and gateway setting, I didn't configure authentication override (Generate cookies and Accept cookies)&lt;/P&gt;&lt;P&gt;For this - It is mandatory to configure authentication override?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;Please suggest to me what I need to do for this.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 20:45:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multifactor-authentication-with-radius/m-p/324385#M82814</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-04-22T20:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect multifactor authentication with RADIUS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multifactor-authentication-with-radius/m-p/324386#M82815</link>
      <description>&lt;P&gt;The PAN-OS version is 8.1.8 when I found the known issue:-&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;PAN-97757&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;DIV class="p"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&lt;BR /&gt;GlobalProtect authentication fails with an Invalid username/password error (because the user is not found in Allow List) after you enable GlobalProtect authentication cookies and add a RADIUS group to the Allow List of the authentication profile used to authenticate to GlobalProtect.&lt;BR /&gt;Workaround: Disable GlobalProtect authentication cookies. Alternatively, disable (clear) Retrieve user group from RADIUS in the authentication profile and configure group mapping from Active Directory (AD) through LDAP&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Apr 2020 20:48:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multifactor-authentication-with-radius/m-p/324386#M82815</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2020-04-22T20:48:07Z</dc:date>
    </item>
  </channel>
</rss>

