Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network security administrator is troubleshooting a GlobalProtect VPN connection issue. Users are unable to connect to the GlobalProtect portal, and the portal logs show 'User authentication failed'. The authentication profile on the firewall uses RADIUS. The RADIUS server logs show no authentication attempts from the firewall. Pinging the RADIUS server from the firewall's management interface is successful. What is the MOST likely cause?

  1. AThe firewall's RADIUS server profile has an incorrect server IP or port.
  2. BThe RADIUS server is configured with an incorrect shared secret for the firewall.
  3. CThe firewall's source interface for RADIUS traffic is incorrectly configured or missing a security policy.
  4. DThe GlobalProtect portal is configured with an incorrect authentication profile.
Show answer & explanation

Correct answer: C. The firewall's source interface for RADIUS traffic is incorrectly configured or missing a security policy.

The key information is that the RADIUS server logs show *no authentication attempts* from the firewall, even though ping is successful. This suggests the firewall is not even attempting to send the authentication request to the RADIUS server, despite knowing its IP and being able to reach it. This often happens if the source interface for the RADIUS server profile is not correctly specified, or if there's a security policy blocking the outbound RADIUS (UDP 1812/1813) traffic from the firewall's source zone to the RADIUS server's zone.

Why the other options are wrong

  • A. If the server IP or port was incorrect, the firewall wouldn't be able to ping it successfully (if IP is wrong) or the RADIUS server wouldn't receive anything (if port is wrong), but the issue is *no attempt* at all.
  • B. If the shared secret was incorrect, the RADIUS server logs would show an authentication attempt and then a failure, which is not happening here.
  • D. If the portal had an incorrect authentication profile, it might still attempt to send requests, or fail with a different error. The problem is no attempts are reaching the RADIUS server.

GlobalProtect RADIUS Source Interface

For external authentication like RADIUS, a Palo Alto Networks firewall must have a correctly configured source interface and an allowing security policy to send authentication requests.

  • Even if pingable, authentication traffic might be blocked.
  • Source interface in RADIUS profile dictates egress zone.
  • Security policy must allow UDP 1812/1813 from firewall to RADIUS server.

Memory trick: GlobalProtect needs a 'Right Path' for RADIUS requests.

More Troubleshoot questions