GlobalProtect portal user authentication failed

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

GlobalProtect portal user authentication failed

Cyber Elite
Cyber Elite

we have global protect portal configured and both portal and gateway have same ip assinged.

we have configured RADIUS for auth.

 

Also under Auth profile we have Radius as a profile name

 

When client connects he gets message

 

GlobalProtect portal user authentication failed. Login from: 

Reason: Authentication failed: Invalid username or password, Auth type: profile

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

L2 Linker

Well, there's the obvious explanation that the username or password are incorrect.  But I'm assuming you posted because you know that not to be the case.  Troubleshooting this needs a lot more information, because it could be any number of things at this point.  As a next step, I'd look at the authentications logs on the firewall where you have the portal/gateway.  Under the Monitor tab, this is found under System.  I might further suggest you start with this filter and see if anything in the descriptions gives you a good lead:

 

(( subtype eq auth ) or ( subtype eq globalprotect ))

 

 

View solution in original post

3 REPLIES 3

L2 Linker

Well, there's the obvious explanation that the username or password are incorrect.  But I'm assuming you posted because you know that not to be the case.  Troubleshooting this needs a lot more information, because it could be any number of things at this point.  As a next step, I'd look at the authentications logs on the firewall where you have the portal/gateway.  Under the Monitor tab, this is found under System.  I might further suggest you start with this filter and see if anything in the descriptions gives you a good lead:

 

(( subtype eq auth ) or ( subtype eq globalprotect ))

 

 

Typo in the RADIUS shared secret?

Thanks everyone for the help.

User belongs to different group added the right profile under radius and all is good now.

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 61009 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!