Check the authentication rule and identity mapping:
show authentication rule
show authentication scheme
show user group
diagnose wad user list
Verify the rule matches the client and selects the intended scheme. Review the matched traffic policy and required user/group. For LDAP or RADIUS, inspect the configured server object, reachability, and server-side logs. For LDAPS, verify the certificate chain and server name.
For Kerberos, verify the proxy FQDN, SPN/keytab, DNS and time synchronization. For SAML, inspect the IdP result and returned identity/group claims. An LDAP password test does not validate Kerberos tickets, SAML, MFA, or proxy policy matching.
Test the relevant backend once:
diagnose test authserver ldap ?
diagnose test authserver radius ?
Use the argument syntax shown on the target build with an authorized test account. The generated CLI reference documents these command families but does not enumerate their arguments. Avoid repeated tests against a locked account and exclude passwords from saved transcripts.
Backend success with browser failure shifts the investigation toward rule selection, group resolution, client credentials, or the chosen authentication method. A timeout points toward connectivity or backend availability; a rejection requires the server-side reason, such as invalid credentials, expiry, or lockout.
Collect one short authentication debug output:
For a failure handled by FNBAMD, coordinate with other administrators before resetting debug settings. Start logging, reproduce once, and stop immediately; these diagnostics may include sensitive identity information and unrelated login attempts.
diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application fnbamd -1
diagnose debug enable
After reproducing the failure, stop and clean up:
diagnose debug disable
diagnose debug reset
diagnose debug console timestamp disable
If the failure is in WAD, Kerberos, SAML, or the client before FNBAMD is invoked, an empty FNBAMD trace is inconclusive. Request a client-filtered WAD or method-specific trace using the syntax for that build. Do not enable unrestricted verbose WAD logging on a busy proxy.
|