SSL VPN is working fine with Local Authentication, but not with Radius Server,.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

SSL VPN is working fine with Local Authentication, but not with Radius Server,.

L4 Transporter

Hi Team,.

               We have installed PA 2050 box at our client place in which SSL VPN is configured for remote access. Working fine with Local Authentication but not with Radius Authentication, in PaloAlto system logs, it is showing authentication failed. But we are not able to see any logs in Radius Server 2003. Onceagain I checked shared secret, IP address and Port, it is same in both Radius server and PaloAlto Device. As i don't have much knowledge on radius server it is difficult to identify the problem. Is there any perticuler document for integrating Radius server with PaloAlto Firewall.

Radius server is in same subnet, domain and also reachable from PaloAlto management port. Also created IAS on Server, Is there any extra configuration is required to solve this issue?plese do the needful,.

Thank you

Gururaj.

1 accepted solution

Accepted Solutions

Not applicable
3 REPLIES 3

L5 Sessionator

Have the following command running:

tail follow yes mp-log authd.log

and authenticate the user against AD. These logs will indicate the reason for failure. Please paste the output here.

Not applicable

Did you take a look at this document : https://live.paloaltonetworks.com/docs/DOC-2909 ?

Hi npare,..

Thank you for your reply, It helped me to fix the problem. The problem was with Radius server.

  • 1 accepted solution
  • 2417 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!