Profle vs sequence GlobalProtect Authenticate setting

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Profle vs sequence GlobalProtect Authenticate setting

L0 Member

Condition: we have two group local and Radius,

Question:

Could we know will the GlobalProtect VPN can first verify Radius(user) if it is fail then jump to verify Local(user).

Below setting is right or not (after our testing, Radius fail then it will not jump to Local verification.

Profile_step.png

 

 

 

 

We set Authentication Sequence Radius Local, then verify if Radius fail then continue to local verify, then user can connect and login VPN.

sequence_step2.png

sequence_step1.png

 

My Question is could we use below setting to verify Radius and Local at the same time, if Radius verify fail then continue verify Local?  

Profile_step.png

 

1 REPLY 1

Community Team Member

Hi @S.Lin078062 ,

 

Configuring multiple client authentication options directly under the GP Portal or Gateway Auth tabs is not the same as using an authentication sequence. If multiple profiles are configured there with the same OS type (for example Any), the firewall will only attempt the first matching authentication profile.

 

If you want the firewall to try RADIUS first and then Local if it fails, you would need to create an Authentication Sequence under Device > Authentication Sequence. The fw will then process the authentication profiles sequentially from top to bottom. 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 88 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!