<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sharing a radius authentication-profile from panorama to a vsys-enabled firewall ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sharing-a-radius-authentication-profile-from-panorama-to-a-vsys/m-p/11903#M8751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, this is not a bug and happens to be a limitation of the current Panorama design. You are absolutely correct about the objects being pushed into vsys-contexts and not the "shared" device context. This is where the auth profile needs to be for selection inside Device &amp;gt; Setup for enabling RADIUS auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now you will need to create the profile on each box where you wish to use this authentication mechanism. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are looking at enchancing the Panorama architecture to support pushing objects to non-vsys contexts in a future release. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the inconvienence.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jul 2011 17:36:42 GMT</pubDate>
    <dc:creator>mschuricht</dc:creator>
    <dc:date>2011-07-28T17:36:42Z</dc:date>
    <item>
      <title>Sharing a radius authentication-profile from panorama to a vsys-enabled firewall ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sharing-a-radius-authentication-profile-from-panorama-to-a-vsys/m-p/11902#M8750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I define a shared radius-authentication-profile on panorama , this profile gets published into all my panorama managed firewall.&lt;/P&gt;&lt;P&gt;So far so good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when this gets pushed to a vsys-enabled firewall, then the authentication profile is pushed only into the vsys-contexts and not into the device context.&lt;/P&gt;&lt;P&gt;-&amp;gt; This has as result that the radius authentication profile in question can not be used as device authentication-profile for non-local administators on that firewall. It is simply not visible in the device-context, so it can not be selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a bug are normal behaviour&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;btw , we are on 4.0.3.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 13:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sharing-a-radius-authentication-profile-from-panorama-to-a-vsys/m-p/11902#M8750</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-07-28T13:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sharing a radius authentication-profile from panorama to a vsys-enabled firewall ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sharing-a-radius-authentication-profile-from-panorama-to-a-vsys/m-p/11903#M8751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, this is not a bug and happens to be a limitation of the current Panorama design. You are absolutely correct about the objects being pushed into vsys-contexts and not the "shared" device context. This is where the auth profile needs to be for selection inside Device &amp;gt; Setup for enabling RADIUS auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now you will need to create the profile on each box where you wish to use this authentication mechanism. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are looking at enchancing the Panorama architecture to support pushing objects to non-vsys contexts in a future release. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the inconvienence.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 17:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sharing-a-radius-authentication-profile-from-panorama-to-a-vsys/m-p/11903#M8751</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2011-07-28T17:36:42Z</dc:date>
    </item>
  </channel>
</rss>

