- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-02-2024 06:02 PM - edited 05-02-2024 06:04 PM
Hello, everyone.
Firewall has OS of 10.2.4-H2.
When TACACS account to connect to Firewall SSH, the login succeeds, but there is an issue that closes the session immediately.
In Firewall System-log, authentication and authorization were successful and it was confirmed that the Superuser role was granted..
However, a "create-admin-acct-error" log with Critical Severity is created. - "Failed to create local user account for admin user: username" in system-log.
WEB GUI is connected normally, but only SSH Session issues.
the log was generated as below in TSF File syslog-system.
sshd[13371]: error: PAM: User account has expired for [username] from [IP].
HA Peer device doesn't have this issue at all. It happens only on this firewall.
Is there any way to solve?
04-13-2026 01:24 PM
You can try these commands if you haven't already solved I guess since it's an old post but I hade the exact same issue.
> Remove Lock Files: delete authentication system-lock-files
> Restart the Authentication Daemon: debug software restart process authd
04-16-2026 04:00 AM
Check the local admin account as it seems flaged as expired, additionally, you can clear cache by command "debug authentication clear-cache all".
Finally if the issue not resolved, you can try restart the management plane "debug software restart process management-server".
On the other hand, could check you panos release as some of them has a known bug in TACACS authentication.
04-19-2026 11:23 PM
I created a TAC case and these commands solved it and they came from TAC engineer.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

