Want to learn the best practice for configuring Chromebooks with 802.1X authentication?

Sign up for a Webinar!

Palo Alto RADIUS Accounting Configuration Steps

Introduction

This document explains the steps required to test RADIUS Accounting events forwarded to Palo Alto firewall.

Prerequisites

To forward RADIUS events to Palo Alto firewall port forwarding should be configured on the ISP router.

  • Port following should be configured on the ISP router.

Configuring the ISP Router

To configurate port forwarding in the ISP router, follow the given steps.

  1. Create a NAT – Virtual Server Configuration in the ISP router as follows: Attributes -
    1. External IP Address – SecureW2 NAT IP
    2. External Start Port – User desired
    3. External End Port – User desired
    4. Protocol – TCP
    5. Server IP Address – LAN IP of the PaloAlto firewall which is connected to the ISP router
    6. Source Port - 80

Configuring the Palo Alto Firewall

The Palo Alto firewall helps SSL encrypted traffic and applications Perform the following configurations to receive RADIUS accounting events.

  1. Navigate to Network > Network Profiles > Interface Management > Management.
  2. Add the CENT NAT IP as shown in the following image.

Configuring the Management Portal

  1. Login to the JoinNow Management Portal.
  2. Go to External Connections > Configuration.
  3. Click the Add External Connection button.
  4. In the Name field, enter a name for the connection.
  5. In the Display Description field, enter a suitable description for the connection.
  6. From the Type drop down list, select Palo Alto.
  7. Click Save. The page reloads and the Configuration tab is displayed.
  8. Select the Configuration tab:
    1. In the Firewall URL field, enter the server URL.
    2. In the Username and Password fields, enter the credentials.
    3. Click the Validate button to verify the credentials and the connection.
  9. Click Update.

Here is a sample of RADIUS Accounting events for Login and Logout sent to the Palo Alto Firewall for the above configurations.