<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Authentication Failure: Timeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-failure-timeout/m-p/433155#M95831</link>
    <description>&lt;P&gt;Issue: Authentication failure when using AD Account&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log: Authentication Timeout to server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;PanOS Version: 10.1.1&lt;/P&gt;&lt;P&gt;Panorama is not used&amp;nbsp;&lt;/P&gt;&lt;P&gt;NPS Installed on Windows Server 2016&lt;/P&gt;&lt;P&gt;Radius Server Profile Created&lt;/P&gt;&lt;P&gt;Authentication Profile Created&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin Role Created&lt;/P&gt;&lt;P&gt;Linked in Setup&lt;/P&gt;&lt;P&gt;NPS Client and Policy Created( 25461 - uses created admin role, uses PAP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tested:&lt;/P&gt;&lt;P&gt;Tested Policies on dev and worked&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible issue:&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Authentication setting has second gear that sates "Stack Override:" not present in dev.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is it Possible that the override is changing my settings and pointing to a local login instead?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2021 17:45:54 GMT</pubDate>
    <dc:creator>ColeBryner</dc:creator>
    <dc:date>2021-09-10T17:45:54Z</dc:date>
    <item>
      <title>Radius Authentication Failure: Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-failure-timeout/m-p/433155#M95831</link>
      <description>&lt;P&gt;Issue: Authentication failure when using AD Account&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log: Authentication Timeout to server&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;PanOS Version: 10.1.1&lt;/P&gt;&lt;P&gt;Panorama is not used&amp;nbsp;&lt;/P&gt;&lt;P&gt;NPS Installed on Windows Server 2016&lt;/P&gt;&lt;P&gt;Radius Server Profile Created&lt;/P&gt;&lt;P&gt;Authentication Profile Created&amp;nbsp;&lt;/P&gt;&lt;P&gt;Admin Role Created&lt;/P&gt;&lt;P&gt;Linked in Setup&lt;/P&gt;&lt;P&gt;NPS Client and Policy Created( 25461 - uses created admin role, uses PAP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tested:&lt;/P&gt;&lt;P&gt;Tested Policies on dev and worked&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible issue:&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Authentication setting has second gear that sates "Stack Override:" not present in dev.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Is it Possible that the override is changing my settings and pointing to a local login instead?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 17:45:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-failure-timeout/m-p/433155#M95831</guid>
      <dc:creator>ColeBryner</dc:creator>
      <dc:date>2021-09-10T17:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication Failure: Timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-failure-timeout/m-p/433234#M95840</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am running 10.1.1 and I too have the same orange "override" gear, so that is part of the operating system for 10.1.1&lt;/P&gt;&lt;P&gt;If you have your auth profile to Radius, then should be working.&lt;/P&gt;&lt;P&gt;CLI into the firewall and issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tail follow yes mp-log authd.log (confirm my synatax..) and watch as your user attempts to authenticate.&lt;/P&gt;&lt;P&gt;just keep in mind that the FW is not failing your authentication... your Radius server is... and the FW merely acts a the messenger to say "invalid username or password" or similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test, try to create a local users (not admin account user) but under Device ==&amp;gt; Local Users.&amp;nbsp; And create an auth profile, pointed back to that local user.&amp;nbsp;&amp;nbsp; If auth works locally (where the FW is the authentication server), but fails when you change to LDAP or Radius, this will confirm/illustrate that either your auth profile is incorrect (IP, shared secret, service account name, port name, etc.)&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 21:40:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-authentication-failure-timeout/m-p/433234#M95840</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-09-10T21:40:49Z</dc:date>
    </item>
  </channel>
</rss>

