I'm revisiting this subject to see if Palo Alto has implemented any changes to allow us to configure authentication so it uses Radius as the preferred method but only allows authentication against the local database if Radius is not available. We have tested multiple ways on our Palo firewalls but it always works in performing the sequence even if the Radius server is active. (Allows local users to authenticate if Radius is available but authentication fails.)
... View more