- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-15-2022 07:47 AM
We're configuring authentication and we have a requirement that Local authentication should not work if when radius is available.
Team - is that supported of Palo Alto Firewalls? Let me know if that is possible or any documents would help us.
Thank you
08-15-2022 08:27 AM
Hello there.
The configuration you are looking for is called Authentication Sequence.
You can configure the FW to first check Radius, and if the user fails Radius, to try to use Local.
But.. you cannot make Local NOT work, just because there is a Radius configuration. It is a fail-through mechanism.
Hope that makes sense.
Thank you.
03-13-2025 04:22 PM
I saw this after 3 years, and this one is feasible. It's not uploaded to palo alto documentation. You may follow these steps for this to work.
1.) Create User on Local User Database.
2.) Create Authentication Profile and add your server profile (IP addresses)
3.) Create Auth Sequence, click the exit the sequence on failed authentication, under authentication profile, radius profile should be on top before the local.
4.) Create Administrator, Administrator type dynamic, super user and tick authentication profile to the created auth sequence, not the created auth profile.
5.) Test it out by logging in using local admin - your login will be denied.
6.) Test it out again while radius is temporarily down - your local login should be accepted.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!