<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect-Need use Local database users and PingID  for auth(MFA) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419369#M1513</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;the reason to ask is because there is not a documented answer to cover local databse user usage for PingID, like DUO did it, we are assuming that we can but , we will need to create a lab a provision a VM (do the whole process to validate if is feasible or not the local database of users from the PA) to test if PingID will work with the local DB or not, anyway, if someone tried and did not work , so, can tell us first hand will be great. Anyway if the scenario is not positive we will need to find another solution without add a AD piece for such small population of users.&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 22:29:44 GMT</pubDate>
    <dc:creator>Jose_Espinoza</dc:creator>
    <dc:date>2021-07-14T22:29:44Z</dc:date>
    <item>
      <title>Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419035#M1509</link>
      <description>&lt;P&gt;hello team&lt;/P&gt;&lt;P&gt;We have this small database of users for Global Protect for our staff , however, we will like to add the MFA with PingID, following the configuration steps from vendor alyways mention LDAP as an authentication server, then our question: could we use the local database from the PA and not to jump to an AD server?&lt;/P&gt;&lt;P&gt;did someone had have experienced with this type of deploy that can provide feedback relate?&lt;/P&gt;&lt;P&gt;we know that with DUO or OKTA cannot be done, their KB's state that not.&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 17:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419035#M1509</guid>
      <dc:creator>Jose_Espinoza</dc:creator>
      <dc:date>2021-07-13T17:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419040#M1510</link>
      <description>&lt;P&gt;I, too, am interested in setting up MFA that doesn't touch our inside network. I don't understand why it is such a big deal? 1Password, Google, Microsoft....can't we use ANY of those? I have no desire, or ever will, want to tie my firewall to my internal domain. Ever. We need options.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 17:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419040#M1510</guid>
      <dc:creator>Maynard-Fayetteville</dc:creator>
      <dc:date>2021-07-13T17:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419240#M1511</link>
      <description>&lt;P&gt;The pingid docs state...&lt;/P&gt;&lt;OL class="ol"&gt;&lt;LI&gt;PingFederate authenticates the user’s credentials with the user repository, such as an LDAP server, as first-factor authentication.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I don't see why you cannot add a local users auth profile to the MFA. Or indeed any external auth server... &amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps they assume as you are logging into a windoze device you are already a domain member so why not use LDAP. &amp;nbsp;If you are not, then use something else as the first factor.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 05:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419240#M1511</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-14T05:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419369#M1513</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;the reason to ask is because there is not a documented answer to cover local databse user usage for PingID, like DUO did it, we are assuming that we can but , we will need to create a lab a provision a VM (do the whole process to validate if is feasible or not the local database of users from the PA) to test if PingID will work with the local DB or not, anyway, if someone tried and did not work , so, can tell us first hand will be great. Anyway if the scenario is not positive we will need to find another solution without add a AD piece for such small population of users.&lt;/P&gt;&lt;P&gt;cordially&lt;/P&gt;&lt;P&gt;jose&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 22:29:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419369#M1513</guid>
      <dc:creator>Jose_Espinoza</dc:creator>
      <dc:date>2021-07-14T22:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419615#M1514</link>
      <description>&lt;P&gt;I have not tried it but I can't see why it would fail, there are many MFA solutions available, probably hundreds if you include self written solutions so not all scenarios will be scripted. Good Luck with your testing...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 09:22:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419615#M1514</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-07-15T09:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419732#M1516</link>
      <description>&lt;P&gt;thanks, we will try today the set up for PingID, the issue for MFA on PA there is an specific number of vendors that can be integrated, not all of the MFA vendors are supported by PA like google authenticator, etc, I will post here the results of PingID test anyway.&amp;nbsp; cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 17:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/419732#M1516</guid>
      <dc:creator>Jose_Espinoza</dc:creator>
      <dc:date>2021-07-15T17:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect-Need use Local database users and PingID  for auth(MFA)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/441985#M1906</link>
      <description>&lt;P&gt;*ping* did you have any luck?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 19:51:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-need-use-local-database-users-and-pingid-for-auth/m-p/441985#M1906</guid>
      <dc:creator>Maynard-Fayetteville</dc:creator>
      <dc:date>2021-10-19T19:51:02Z</dc:date>
    </item>
  </channel>
</rss>

