Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network engineer is investigating an issue where users are unable to authenticate to a new external RADIUS server configured on a Palo Alto Networks firewall. The firewall's authentication server profile for RADIUS is correctly configured with the server IP, shared secret, and port. The authentication profile is referencing this server profile. However, when users attempt to authenticate, the firewall logs show 'authentication failed for user <username> via RADIUS server, reason: server not responding'. What is the MOST likely cause?

  1. AThe authentication profile is not correctly applied to the relevant services (e.g., GlobalProtect, Captive Portal).
  2. BThe RADIUS server is using an unsupported authentication protocol (e.g., MS-CHAPv1).
  3. CA security policy is blocking the firewall's outbound RADIUS authentication requests to the RADIUS server.
  4. DThe shared secret configured on the firewall does not match the one on the RADIUS server.
Show answer & explanation

Correct answer: C. A security policy is blocking the firewall's outbound RADIUS authentication requests to the RADIUS server.

The error 'server not responding' directly indicates that the firewall is unable to establish communication with the RADIUS server. Even if the server profile details are correct, an intervening security policy preventing the firewall from sending its authentication requests (UDP port 1812/1813) to the RADIUS server would cause this symptom.

Why the other options are wrong

  • A. If the authentication profile wasn't applied, users wouldn't even be prompted to authenticate or the firewall would fall back to a different method, not report 'server not responding'.
  • B. An unsupported protocol would typically lead to an 'authentication failed' error after a response from the server, not a 'server not responding' error.
  • D. A mismatched shared secret would result in an 'authentication failed' or 'invalid credentials' error from the RADIUS server, implying the server was reached and responded.

External Authentication Connectivity

For external authentication services like RADIUS, the Palo Alto Networks firewall must have network connectivity and a permissive security policy to send authentication requests to the server.

  • RADIUS uses UDP ports 1812 (auth) and 1813 (accounting).
  • Firewall must be able to reach the RADIUS server IP.
  • Outbound security policy from firewall zone to RADIUS server zone is critical.

Memory trick: The firewall is calling, but the line is dead. Check the path and permissions!

More Troubleshoot questions