- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-24-2023 05:09 AM - edited 11-24-2023 05:26 AM
Hi @cullums ,
To see the username for failed authentications, you should uncheck "Disclose invalid usernames" under Administration > System > Settings > Security Settings.
To see why the user is failing you should click on the details page icon under Operations > TACACS > Live Logs.
I use TACACS for my NGFW administrative logon, and it works fine. There are a couple ways to do it:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMYmCAO
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/authentication-types/tacacs
Thanks,
Tom
Edit: TACACS+ with CHAP will not work with AD because PA uses CHAP/MD5. TACACS+ with PAP works fine with AD. https://live.paloaltonetworks.com/t5/general-topics/tacacs-cisco-ise-config/td-p/230962/page/2