<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius authentication with Clearpass for Firewall Webgui in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431693#M95132</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;&amp;nbsp;&amp;nbsp; To answer your "another question," you have 2 options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Configure the administrator under Device &amp;gt; Administrators and specify the Authentication Profile, in your example - RADIUS.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Configure the Authentication Profile under Device &amp;gt; Setup &amp;gt; Management &amp;gt; Authentication Settings if you do not want to create a local account for every administrator.&amp;nbsp; Only RADIUS, TACACS+ and SAML methods are supported.&amp;nbsp; With this method you will need to create an attribute on the authentication server that defines the role of the administrator.&amp;nbsp; You should also restrict the users as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Sep 2021 20:59:57 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-09-06T20:59:57Z</dc:date>
    <item>
      <title>Radius authentication with Clearpass for Firewall Webgui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431614#M95112</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Followed this KB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS6CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClS6CAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The authentication shows successful on the inbound to Clearpass and meets all the policies required for successful login.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Inked15_LI.jpg" style="width: 517px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36098i012FB202AFFE937D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Inked15_LI.jpg" alt="Inked15_LI.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="16.png" style="width: 503px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36099i59965E09C2484A4B/image-dimensions/503x297/is-moderation-mode/true?v=v2" width="503" height="297" role="button" title="16.png" alt="16.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However the Palo sits at the login then eventually fails after about 5-10 seconds and indicates incorrect login credentials.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="14.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36097i73389AC722352809/image-dimensions/500x279/is-moderation-mode/true?v=v2" width="500" height="279" role="button" title="14.png" alt="14.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Palo System logs indicate Authentication failure&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;failed authentication for user '&lt;STRONG&gt;test.user&lt;/STRONG&gt;'. auth profile 'PALO-CLEARPASS', vsys 'shared', server profile '&lt;SPAN&gt;PALO-Clearpass&lt;/SPAN&gt;', server address '10.x.x.x', auth protocol 'PAP', From: 10.x.x.x.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Auth d logs shows&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:44.886 +1000 debug: pan_authd_radius_create_req_payload(pan_authd_radius.c:230): username: &lt;STRONG&gt;test.user&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:44.886 +1000 debug: pan_make_radius_request_buf(pan_authd_radius_prot.c:390): RADIUS request type: PAP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:49.886 +1000 debug: auth_svr_timeout_sent_request(pan_auth_svr.c:272): timeout: authd id=6842217317271730159, username=&lt;STRONG&gt;test.user&lt;/STRONG&gt;, protocol req id=123, retries=3 (max allowed retries #: 3), elapsed sec=13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(max allowed secs: 180)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:49.886 +1000 debug: pan_auth_response_process(pan_auth_state_engine.c:4290): auth status: auth timed out&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:49.886 +1000 debug: pan_auth_response_process(pan_auth_state_engine.c:4529): Auth FAILED for user "&lt;STRONG&gt;test.user&lt;/STRONG&gt;" thru &amp;lt;"PALO-CLEARPASS", "shared"&amp;gt;: remote server 10.x.x.x.x of server profile "PALO-Clearpas&lt;/SPAN&gt;&lt;SPAN&gt;s" is down, or in retry interval, or request timed out (elapsed time 13 secs, max allowed 180 secs)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:49.886 +1000 debug: pan_auth_response_process(pan_auth_state_engine.c:4571): Authentication failed: &amp;lt;profile: "PALO-CLEARPASS", vsys: "shared", username "&lt;STRONG&gt;test.user&lt;/STRONG&gt;"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;2021-09-03 17:55:49.886 +1000 Error:&amp;nbsp; pan_set_admin_user_stat(pan_auth_admin_login_stat.c:260): Admin user "test.user" home dir "/opt/pancfg/home/test.user" has NOT created yet&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;2021-09-03 17:55:49.886 +1000 Error:&amp;nbsp; pan_auth_send_auth_resp(pan_auth_server.c:646): pan_set_admin_user_stat("test.user", False)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2021-09-03 17:55:49.887 +1000 failed authentication for user '&lt;STRONG&gt;test.user&lt;/STRONG&gt;'.&amp;nbsp;&amp;nbsp; auth profile 'PALO-CLEARPASS', vsys 'shared', server profile 'PALO-Clearpass', server address '10.x.x.x.', auth protocol 'PAP', From: 10.x.x.x.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be causing this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also another question is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When using RADIUS authentication for management(GUI/SSH) of firewall&amp;nbsp; do you add the administrator&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;test.user&lt;/STRONG&gt;&lt;/SPAN&gt; manually in administrators of GUI and specify the authentication profile for RADIUS on a per-user basis???&lt;BR /&gt;- GUI &amp;gt; Device &amp;gt; Administrators &amp;gt; adding the user there??&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 11:52:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431614#M95112</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2021-09-04T11:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication with Clearpass for Firewall Webgui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431644#M95121</link>
      <description>&lt;P&gt;Your error is still on Last Pass:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Auth FAILED for user "&lt;STRONG&gt;test.user&lt;/STRONG&gt;" thru &amp;lt;"PALO-CLEARPASS", "shared"&amp;gt;: remote server 10.x.x.x.x of server profile "PALO-Clearpas&lt;/SPAN&gt;&lt;SPAN&gt;s" is down, or in retry interval, or request timed out (elapsed time 13 secs, max allowed 180 secs)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 15:10:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431644#M95121</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-09-04T15:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication with Clearpass for Firewall Webgui</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431693#M95132</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/114565"&gt;@Jatin.Singh&lt;/a&gt;&amp;nbsp;&amp;nbsp; To answer your "another question," you have 2 options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Configure the administrator under Device &amp;gt; Administrators and specify the Authentication Profile, in your example - RADIUS.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Configure the Authentication Profile under Device &amp;gt; Setup &amp;gt; Management &amp;gt; Authentication Settings if you do not want to create a local account for every administrator.&amp;nbsp; Only RADIUS, TACACS+ and SAML methods are supported.&amp;nbsp; With this method you will need to create an attribute on the authentication server that defines the role of the administrator.&amp;nbsp; You should also restrict the users as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/administrative-authentication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 20:59:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-with-clearpass-for-firewall-webgui/m-p/431693#M95132</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-06T20:59:57Z</dc:date>
    </item>
  </channel>
</rss>

