I am using ISE as RADIUS Server for PaloAlto Firewall login authentication. Whenever I am trying to login with invalid username, it seems ISE is sending some MFA(OTP/Challenge). The reason I am think so is that I am seeing MFA/OTP workflow getting triggered on Firewall. I am using PEAP-GTC Protocol.
I have checked ISE live logs and did not get any information what ISE is responding with. I have set If Auth fail to REJECT in authentication policy on ISE. I can't leverage packet capture since the traffic uses TLS.