<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Authentication issues with Symantec VIP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396019#M91333</link>
    <description>&lt;P&gt;Is the RADIUS profile going to Symantec VIP and then to OKTA MFA (please provide info how the RADIUS works and if you are making the SYMANTEC VIP to talk with OKTA ask Symantec if this is possible at all)? Why not directly integrate Okta MFA without RADIUS as this is supported by palo alto?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-multi-factor-authentication/configure-mfa-between-okta-and-the-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-multi-factor-authentication/configure-mfa-between-okta-and-the-firewall&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Apr 2021 13:14:46 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2021-04-06T13:14:46Z</dc:date>
    <item>
      <title>GP Authentication issues with Symantec VIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/395804#M91307</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are running Palo Alto Global Protect with Symantec VIP MFA. We have run this for quite some time now and it has been stable until recently.&lt;/P&gt;&lt;P&gt;We are seeing random errors appearing on one of the validation servers. It seems Palo is sending the request but Symantec is dropping it. A restart of the validation service on VIP EG fix the issue temporarily but it appears atleast once a day everyday.&lt;/P&gt;&lt;P&gt;I have taken a wireshark capture when the error was happening. You can clearly see the firewall making the request with no response from the server and from packet 7527, this is where i restarted the validation service on Syamentec running on the port you can see response going to the firewall.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Understand this looks more like a Symantec issue but the change was made on the firewall which triggered these errors. On Palo i have started using Authentication sequence which goes through 3 profiles. 2 X LDAP and last one Radius. 1 x LDAP is not in use and i will be deleting that.&lt;/P&gt;&lt;P&gt;The radius one has been recently added using Okta MFA. Surprisingly when i remove the profile from the sequence on Palo no errors are seen on Symantec VIP MFA server. I have tested this a number of times now at the cost of some operational impact :(. No other way to reproduce the error. Ignore my feeble attempts to mask the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Firewall requests.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30720i59CD7B528C08A097/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Firewall requests.png" alt="Firewall requests.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;SYMANTEC LOGs:&lt;/P&gt;&lt;DIV&gt;INFO "2021-03-22 12:54:30.027 GMT+1100" 0.0.0.0 RADIUS_SCC_ALL:1901 0 0 "text=Sending Acces-Reject for user [amarsh] , reason=47; Invalid Input." Thread-2932 VSAuthOTPStandardControllerImpl.cpp&lt;/DIV&gt;&lt;DIV&gt;AUDIT "2021-03-22 12:54:30.027 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 24597 "text=Access DENIED Invalid Input. ,reason=47; Invalid Input." Thread-2932 VSValidationEngine.c&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:36.953 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [106_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:39.953 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [107_172.18.17.254_46753_] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:39.953 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [108_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:41.954 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [109_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:44.954 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [110_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:44.954 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [111_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:55:50.955 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [112_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:56:01.956 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [113_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:56:03.956 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [114_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:56:04.957 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [115_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;DIV&gt;ERROR "2021-03-22 12:56:09.958 GMT+1100" 172.18.17.254 RADIUS_SCC_ALL:1901 0 0 "text=RADIUS request with unique Id [116_172.18.17.254_46753] has timed-out. Dropping the request. Will be purged." Thread-2960 VSAuthManageAuthnRequests.cpp&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Following was done:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Server rebooted but the issue resurfaced next day.&lt;/DIV&gt;&lt;DIV&gt;Recreated the service on a different port in Symantec but the issue appeared next day on the new service as the okta profile was still attached.&lt;/DIV&gt;&lt;DIV&gt;Timeout increased to 120s but it resurfaced again next day.&lt;/DIV&gt;&lt;DIV&gt;Removed Okta radius profile - fixed the issue, 5 days and counting.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Need to reenable as i want to use multiple auth profiles and really want to use this feature due to people logging in from different domains and using different MFAs.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Apr 2021 14:03:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/395804#M91307</guid>
      <dc:creator>Palo_lover</dc:creator>
      <dc:date>2021-04-05T14:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: GP Authentication issues with Symantec VIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396019#M91333</link>
      <description>&lt;P&gt;Is the RADIUS profile going to Symantec VIP and then to OKTA MFA (please provide info how the RADIUS works and if you are making the SYMANTEC VIP to talk with OKTA ask Symantec if this is possible at all)? Why not directly integrate Okta MFA without RADIUS as this is supported by palo alto?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-multi-factor-authentication/configure-mfa-between-okta-and-the-firewall" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/authentication/configure-multi-factor-authentication/configure-mfa-between-okta-and-the-firewall&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 13:14:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396019#M91333</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-06T13:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: GP Authentication issues with Symantec VIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396031#M91334</link>
      <description>No. Symantec doesnt talk with Okta as there is no value in doing that. they&lt;BR /&gt;are independent. I have the sequence like below:&lt;BR /&gt;&lt;BR /&gt;Symantec Radius on port 1901&lt;BR /&gt;Symantec Radius on port 19xx (for a different user group. this isnt being&lt;BR /&gt;used)&lt;BR /&gt;Okta Radius&lt;BR /&gt;&lt;BR /&gt;I have also selected the option where it picks the authentication profile&lt;BR /&gt;using domain when a user enters their username. So the request doesnt have&lt;BR /&gt;to go through options first second and then third. It goes straight to 3 as&lt;BR /&gt;here is where the user puts his mail as his username and i can see Palo go&lt;BR /&gt;straight to Okta. So then it becomes completely bewildering if the request&lt;BR /&gt;doesnt even go to Symantec and it gets stuck.&lt;BR /&gt;</description>
      <pubDate>Tue, 06 Apr 2021 14:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396031#M91334</guid>
      <dc:creator>Palo_lover</dc:creator>
      <dc:date>2021-04-06T14:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: GP Authentication issues with Symantec VIP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396145#M91343</link>
      <description>&lt;P&gt;My suggestion is to try the Okta MFA without RADIUS as it is supported by Palo Alto and test and say if the issue is still there.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 22:03:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-authentication-issues-with-symantec-vip/m-p/396145#M91343</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-04-06T22:03:24Z</dc:date>
    </item>
  </channel>
</rss>

