Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootEasy

A network administrator is troubleshooting an issue where users are unable to access internal resources using their domain credentials. The Palo Alto Networks firewall is configured to use an external RADIUS server for authentication. When testing the RADIUS server profile from the firewall, the test fails with a 'Connection Timeout' error. What is the MOST likely cause of this issue?

  1. ARADIUS server is unreachable due to network connectivity or firewall rules.
  2. BIncorrect user group mapping on the firewall.
  3. CThe RADIUS server is configured to use an unsupported authentication protocol.
  4. DIncorrect RADIUS shared secret.
Show answer & explanation

Correct answer: A. RADIUS server is unreachable due to network connectivity or firewall rules.

A 'Connection Timeout' error specifically indicates that the firewall could not establish a network connection to the RADIUS server. This points to a network path issue, such as routing problems or an intervening firewall blocking the connection.

Why the other options are wrong

  • B. User group mapping occurs after successful authentication. If the connection times out, authentication hasn't even begun.
  • C. An unsupported authentication protocol would likely result in an 'authentication failed' or 'protocol mismatch' error, not a 'connection timeout'.
  • D. An incorrect shared secret would typically result in an 'authentication failed' or 'access denied' error, not a 'connection timeout'.

External Auth Connectivity

Troubleshooting external authentication connectivity involves verifying network reachability and basic communication between the firewall and the authentication server (e.g., RADIUS, LDAP).

  • Connection Timeout = no network path.
  • Authentication Failed = bad credentials/config.
  • Firewall rules can block auth traffic.

Memory trick: Before you can knock, you need to find the door.

More Troubleshoot questions