Troubleshoot the Palo Alto Network VPN integration
Examine authentication logs:
- Open a web browser and navigate to the GlobalProtect Admin Page, or open the Palo Alto Networks Panorama.
- Navigate to Monitor > Authentication.
- In the search filter enter: subtype eq Radius.
- Open the Palo Alto Networks Administrative Shell and run the following commands:
- debug authentication on dump
- tail follow yes lines 20 mp-log authd.log
- Click enter to run the test. Review the logs for detailed output.
Open the Palo Alto Networks Administrative Shell and run the following command:test authentication authentication-profile <profile name> username <username> password
Replace <profile name> and <username> with the values for your organization.
The command line test of the Authentication Profile does not support a second- factor challenge.
Receiving a second-factor challenge confirms that the configuration is working.