You can configure
RADIUS authentication
for end users and firewall or Panorama administrators. For administrators,
you can use RADIUS to manage authorization (role and access domain
assignments) by defining
Vendor-Specific Attributes (VSAs). You
can also use RADIUS to implement
Multi-Factor
Authentication (MFA) for administrators and end users. To
enable RADIUS authentication, you must configure a RADIUS server
profile that defines how the firewall or Panorama connects to the
server (see Step 1 below). You then assign the server profile to
an authentication profile for each set of users who require common
authentication settings (see Step 5 below). What you do with the
authentication profile depends on which users the RADIUS server
authenticates:
End users—Assign the authentication
profile to an authentication enforcement object and assign the object
to Authentication policy rules. For the full procedure, see
Configure
Authentication Policy.
You can also configure client systems to send RADIUS Vendor-Specific Attributes (
VSAs) to the RADIUS server by
assigning the authentication profile to a GlobalProtect portal or gateway.
RADIUS administrators can then perform administrative tasks based on those
VSAs.