Palo Alto GlobalProtect - multiple Radius servers

I’ve been using the Palo Alto SSL VPN application with the configuration on 1 server. This weekend I added another server for Load Balancing/FailOver. I copied the Duo configuration to the new server, started the DuoAuthProxy service, and added the new server to the Palo Alto Radius Server Profile with the correct secret and port. When the original server is shut down and the new up, I’m not prompted for a Duo 2fa. I’ve confirmed my traffic is being received and allowed by the firewall. Any one else ran into this issue?