Authentication Sequence problem

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Authentication Sequence problem

L2 Linker

I configured DUO Proxy for GloablProtect MFA redundancy on our PA 850 firewall using Authentication Sequence. This post shows how I configured: Configure two duo proxy servers for Palo alto firewall MFA redundancy – Net/PC How to (howtonetworki...

 

The problem I have is when the top Authentication profile or DUO Proxy server is down, then the user can't login to GloablProtect. The DUO Proxy server and PA authentication profile is not the issue because I can run the test command successfully. 

 

test authentication authentication-profile <authentication-profile-name> username <username> password
 

 Alos, if I move the second profile (DUO Authentication-2 in my example) to the top, it works.

boblin_1-1683767742215.png

The problem is if the top authentication DUO proxy server (DUO Authentication-2) is down, no one can't login.  MONITOR>Logs>System doesn't have authentication information. If I move the second authentication profile (DUO Authentication in my example) to the top, then it works again. I think it is Authentication Sequence problem but can't figure out how to fix it.

 

 

 

 

Bob Lin, Chicagotech-MVP, MCSE & CNE
Data recovery, Windows OS Recovery, Networking, and Computer Troubleshooting on
http://www.ChicagoTech.net
How to Install and Configure Windows, VMware, Virtualization and Cisco on
http://www.HowToNetworking.com
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@boblin,

That guide doesn't have you modifying the authentication timeout value which will cause this behavior. By default GlobalProtect's timeout is 30 seconds, you'll need to adjust things a bit to account for the delay being introduced by the authentication sequence and the down host.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&lang=en_US%E2%80%A...

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@boblin,

That guide doesn't have you modifying the authentication timeout value which will cause this behavior. By default GlobalProtect's timeout is 30 seconds, you'll need to adjust things a bit to account for the delay being introduced by the authentication sequence and the down host.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HBufCAG&lang=en_US%E2%80%A...

I fixed the problem by adjusting the timeout. Thank you!

Bob Lin, Chicagotech-MVP, MCSE & CNE
Data recovery, Windows OS Recovery, Networking, and Computer Troubleshooting on
http://www.ChicagoTech.net
How to Install and Configure Windows, VMware, Virtualization and Cisco on
http://www.HowToNetworking.com
  • 1 accepted solution
  • 1358 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!