A network security administrator is troubleshooting an issue where users are unable to authenticate to a new external authentication server (RADIUS). The firewall's authentication profile is configured correctly, and the RADIUS server is reachable. However, authentication attempts consistently fail with a 'server timeout' message in the firewall's authentication logs. Which command on the Palo Alto Networks firewall would be most appropriate to diagnose the communication issue between the firewall and the RADIUS server?
- Atest authentication authentication-profile <profile-name> username <username> password <password>
- Bdebug authentication process
- Cshow system setting authentication
- Dping source <interface> host <radius-server-ip>
Show answer & explanationAnswer & explanation
Correct answer: D. ping source <interface> host <radius-server-ip>
A 'server timeout' suggests that the firewall is sending authentication requests but not receiving a response within the expected timeframe. While the server is 'reachable' in general, the connectivity for the specific RADIUS traffic from the correct source interface needs to be verified. The 'ping source <interface> host <radius-server-ip>' command confirms basic network reachability from the firewall's perspective using the correct egress interface, which is a crucial first step before deep-diving into authentication protocols.
Why the other options are wrong
- A. 'test authentication' attempts a full authentication, but if it's timing out, a more fundamental connectivity test is needed first to isolate the problem.
- B. 'debug authentication process' provides detailed logs of the authentication process, which is useful after confirming basic network reachability.
- C. 'show system setting authentication' displays global authentication settings, not specific connectivity issues to a RADIUS server.
External Auth Connectivity Test
When external authentication (e.g., RADIUS, LDAP) timeouts occur, verifying basic IP connectivity from the firewall's perspective, especially from the correct source interface, is a critical initial troubleshooting step.
- Use 'ping source <interface> host <server-ip>' for basic reachability.
- Ensure routing, firewall rules, and ACLs allow traffic.
- Timeouts often indicate network path issues, not protocol errors.
Memory trick: Ping the source to solve the timeout's course.