Palo Alto VPN client fails RADIUS authentication the first time, every time. Skip to main content
https://support.okta.com/help/answers?id=9062a000000qulbqac&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fanswers
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
James BrischJames Brisch 

Palo Alto VPN client fails RADIUS authentication the first time, every time.

As the title suggests, my Palo Alto GlobalProtect client fails authentication the first time every time.  If done back to back, the client successfully authenticates.  From all of the logs, it appears that the Okta RADIUS agent is denying the first attempt to authenticate.

Any Okta RADIUS/Palo Alto experts out there willing to assist?
Silviu MuraruSilviu Muraru (Okta, Inc.)
Hi,


My name is Silviu and I am a Technical Support Engineer (Tier II) at Okta.
Issues with this kind of recurrence and consistency should be carefully and professionally reviewed, so due to this I recommend you right from the start to open a case with us.

I believe you already consulted the guides here:
--> For Palo Alto Global Protect (Integration via SAML 2.0 SSO Protocol):
http://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html

--> For Radius:
https://help.okta.com/en/prod/Content/Topics/Security/Okta_Radius_App.htm
https://support.okta.com/help/Documentation/Knowledge_Article/Okta_101/Installing-Configuring-the-Okta-RADIUS-Agent
https://help.okta.com/en/prod/Content/Topics/DeploymentGuides/Radius_Server_Agent/radius-server-agent-dg.htm


If I am to pinpoint it seems to be a timeout issue, some sort of latency - not working just the first time and then connecting flawlessly. Also it could be because of an MFA timeout.

To sum it up, we have to take a look at the Radius logs, so my recommendation to you is to open up a case with us to get the necessary answers.

Wish you all the best in your work, James!


Thank You,
Silviu Muraru
Technical Support Engineer | Okta

 
James BrischJames Brisch
Silviu,

I opened a ticket after I saw a similar discussion regarding Cisco VPN and RADIUS.  For your reference the ticket number is: 00376613 and I'll be doing some more troubleshooting today.  I'll update as more information is discovered.

Thanks,

James