- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-03-2026 09:37 PM
Condition: we have two group local and Radius,
Question:
Could we know will the GlobalProtect VPN can first verify Radius(user) if it is fail then jump to verify Local(user).
Below setting is right or not (after our testing, Radius fail then it will not jump to Local verification.
We set Authentication Sequence Radius Local, then verify if Radius fail then continue to local verify, then user can connect and login VPN.
My Question is could we use below setting to verify Radius and Local at the same time, if Radius verify fail then continue verify Local?
03-03-2026 10:01 PM
Hi @S.Lin078062 ,
Configuring multiple client authentication options directly under the GP Portal or Gateway Auth tabs is not the same as using an authentication sequence. If multiple profiles are configured there with the same OS type (for example Any), the firewall will only attempt the first matching authentication profile.
If you want the firewall to try RADIUS first and then Local if it fails, you would need to create an Authentication Sequence under Device > Authentication Sequence. The fw will then process the authentication profiles sequentially from top to bottom.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

