Config admin using radius group.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Config admin using radius group.

L3 Networker

I have VM-100 running panos-11.1.13. currently i have local admins for msp -superusers and 1 customer user with a customer -admin-role profile. customer wants to have mutiple admins controlled by their radius. so radius profile and auth profile is configured. how can i attach admin user group(listed under auth profile) to admin role profile.

I see long way of getting list of users ,configure them attaching radius auth profile and admin role profile. or ldap would be better as i can extract group mapping in user identification.

3 REPLIES 3

Cyber Elite

You can't add groups in your authentication profile

 

For radius auth you can either create local accounts and set an authentication profile, or you can change the device level authentication settings to accept radius credentials. that way the radius server decides which accounts to accept and which attributes to return to the firewall (superuser, device admin,...)

2026-03-17_13-10-06.png

Tom Piens
PANgurus - Strata & Prisma Access specialist

L3 Networker

thanks for the info. Currently I havent setup auth profile under auth setting so radius users were failing -complaining cant find radius profile. i created a radius user under administrator account and this radius user can access firewall. I dont want to create users under administrator so I will go ahead with configuring admin profile under auth setting. But i  have msp administrators on the firewall  who r superusers. My only concern is setting auth profile will not cut off these superuser from logging to fw?

local accounts will remain active (and preferred) while a system authentication profile is active, so make sure there's no overlap 

Tom Piens
PANgurus - Strata & Prisma Access specialist
  • 1736 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!