Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile

L4 Transporter

Global Device/Setup Authentication Settings vs Device/Setup/Authentication Profile

 

Hello good afternoon, thank you very much for the usual collaboration.

 

I have the following doubt, at Global level in Device/Setup Authentication Settings there are parameters such as: Failed Attempts and Lockout Time and also if I create an Authentication profile appears the Account Lockout section, which are also Failed Attempts and Lockout Time settings.

 

Now that this is clear, if I create a local account called:
testadmin01


Then that account, I create it as in Device/Setup/Administrators, I associate it to an Authentication profile ( Local Database ), and in its Account Lockout settings I have configured Failed Attempts with value 3 and Lockout Time: 30 minutes.

 

But also at a global level, i.e. Device/Setup Authentication Settings I have Failed Attempts configured with value 5 and Lockout Time: 30 minutes.

 

Based on the above, which settings, which configurations are superimposed over the other ? the global or the custom authentication profile ? Which of the two is valid, which one has real practical validity?

 

Thank you

 

I remain attentive

 

Best regards

High Sticker
1 accepted solution

Accepted Solutions

Community Team Member

Hi @Metgatz ,

 

This is something that you can easily try out so I went ahead and tested it for you.

 

I use my local user configured with AuthProfile - The user was locked out after reaching the number of Failed Attempts which was configured on the AutProfile, totally ignoring my global lock out settings (which was configured with a lower number).

 

Tested on LAB environment running PAN-OS 10.1.x

 

Hope this helps,

-Kiwi.

 
 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

2 REPLIES 2

Community Team Member

Hi @Metgatz ,

 

This is something that you can easily try out so I went ahead and tested it for you.

 

I use my local user configured with AuthProfile - The user was locked out after reaching the number of Failed Attempts which was configured on the AutProfile, totally ignoring my global lock out settings (which was configured with a lower number).

 

Tested on LAB environment running PAN-OS 10.1.x

 

Hope this helps,

-Kiwi.

 
 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hello @kiwi Excellent, thanks a lot for your time! 

 

Best regards

High Sticker
  • 1 accepted solution
  • 1378 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!