Hi @BPry, I haven't checked with the portal, but when you connect with the Global Protect client to the portal, it authenticates in both portal and gateway. We have the authentication override so we do only one authentication. We don't have ideed authentication sequence, but as far as I know, that's for using different profile. What we have is one authentication profile with one RADIUS server profile that inholds 3 RADIUS servers. As per Palo Alto documentation, when using the Server profile, it will try with the first server for the amount for retries, and then go to the second server. We have configured 5 retires, but after the 3rd one (According to the logs) the client of Global Protect already go the authentication fail and asks the user to re-enter username and password. We may need to configure less retries? Is Global Protect working in a different way when it retries the RADIUS authentication?
... View more