GP VPN users cant connect when we run PAN-OS 8.1

Reply
L2 Linker

Re: GP VPN users cant connect when we run PAN-OS 8.1

My RADIUS logs doesnt seem to change the username like yours does, but there is obviously an issue. I have updated my TAC case with this info so hopefully we can get to the bottom of this soon.

 

L6 Presenter

Re: GP VPN users cant connect when we run PAN-OS 8.1

Thats probably because your radius name is the same as your AD name, My AD name is dotted.

 

so i ran a radius debug and it is not only sending dotted username bur also AD password......   read on....

 

 

OK got it sussed...

 

you need to change the portal app setting  "use single sign on" from "yes" to "no".   default is yes and this never made much difference before but I do know they made a lot of updates to SSO in 8.1 so probably fixed it too much... Ha ha.

 

this is now working for me and breaks again wen SSO is set to yes.

L2 Linker

Re: GP VPN users cant connect when we run PAN-OS 8.1

Brillant! OK i will need to book it this in and test it so i will come back to you soon to confirm it.


Thank you for spending time getting to the bottom of this

Highlighted
L2 Linker

Re: GP VPN users cant connect when we run PAN-OS 8.1

Sorry it has taken so long to reply i have only now had time to update the firewalls, this time to 8.1.7, but the difference was this time around VPN connectivity wasnt affected, so i didnt need to make your suggested changes.

 

I have only just finished the upgrade but i can see SSO is still set to yes, so all i am thinking is maybe this was a bug that was fixed in 8.1.7! I will check the change log

 

Thanks for your help with this 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!