You can configure the firewall to use 
External
Authentication Services for authenticating administrators
who access the firewall or Panorama and end users who access services
or applications through Captive Portal. To ensure that the firewall
does not waste resources by continuously trying to reach an authentication
server that is unreachable, you can set a timeout interval after
which the firewall stops trying to connect. You set the timeout
in the server profiles that define how the firewall connects to
the authentication servers. When choosing timeout values, your goal
is to strike a balance between the need to conserve firewall resources
and to account for normal network delays that affect how quickly
authentication servers respond to the firewall.