<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enable DUO for GlobalProtect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/enable-duo-for-globalprotect/m-p/430633#M1677</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking into enabling DUO for GlobalProtect. I am aware that DUO and Palo Alto supports three ways to enable MFA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DUO's RADIUS proxy server&lt;/P&gt;&lt;P&gt;DUO Access Gateway (DAG)&lt;/P&gt;&lt;P&gt;SAML (e.g., Azure, Okta)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried all 3 of them, and I am leaning more towards SAML since it's just easier and supports the DUO prompts. I have a few questions and I was hoping someone could guide me:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-Whenever I try to authenticate with either method above, I get prompted for DUO twice, one for the portal, and one for the gateway (which makes sense). Is there a way to get around this without using cookies?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-Assuming that cookies are required for question 1, is it ok to use the same certificate to encrypt/decrypt cookies, and also install the certificate along with the private key on the client? Unfortunately we don't have a way of pushing the certs to endpoints, so I have to rely on the firewall doing the installation. I am going to assume yes since it should be the same? Any security risk associated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3-If I have to use cookies + certificate, is it ok to simply use a self signed Root CA for this? Or should it be the root + intermediate + client cert, and use the client cert to install on the device, and the root cert to do the encryption/decryption?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help on this will be greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-08-31 at 7.33.36 PM.png" style="width: 883px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35985iD670849D655E5778/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-08-31 at 7.33.36 PM.png" alt="Screen Shot 2021-08-31 at 7.33.36 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-08-31 at 7.33.54 PM.png" style="width: 816px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35984iD73B9C10995BAE63/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-08-31 at 7.33.54 PM.png" alt="Screen Shot 2021-08-31 at 7.33.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Aug 2021 23:35:54 GMT</pubDate>
    <dc:creator>rt_2018</dc:creator>
    <dc:date>2021-08-31T23:35:54Z</dc:date>
    <item>
      <title>Enable DUO for GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/enable-duo-for-globalprotect/m-p/430633#M1677</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking into enabling DUO for GlobalProtect. I am aware that DUO and Palo Alto supports three ways to enable MFA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DUO's RADIUS proxy server&lt;/P&gt;&lt;P&gt;DUO Access Gateway (DAG)&lt;/P&gt;&lt;P&gt;SAML (e.g., Azure, Okta)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried all 3 of them, and I am leaning more towards SAML since it's just easier and supports the DUO prompts. I have a few questions and I was hoping someone could guide me:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1-Whenever I try to authenticate with either method above, I get prompted for DUO twice, one for the portal, and one for the gateway (which makes sense). Is there a way to get around this without using cookies?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-Assuming that cookies are required for question 1, is it ok to use the same certificate to encrypt/decrypt cookies, and also install the certificate along with the private key on the client? Unfortunately we don't have a way of pushing the certs to endpoints, so I have to rely on the firewall doing the installation. I am going to assume yes since it should be the same? Any security risk associated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3-If I have to use cookies + certificate, is it ok to simply use a self signed Root CA for this? Or should it be the root + intermediate + client cert, and use the client cert to install on the device, and the root cert to do the encryption/decryption?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help on this will be greatly appreciate it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-08-31 at 7.33.36 PM.png" style="width: 883px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35985iD670849D655E5778/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-08-31 at 7.33.36 PM.png" alt="Screen Shot 2021-08-31 at 7.33.36 PM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-08-31 at 7.33.54 PM.png" style="width: 816px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/35984iD73B9C10995BAE63/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-08-31 at 7.33.54 PM.png" alt="Screen Shot 2021-08-31 at 7.33.54 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 23:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/enable-duo-for-globalprotect/m-p/430633#M1677</guid>
      <dc:creator>rt_2018</dc:creator>
      <dc:date>2021-08-31T23:35:54Z</dc:date>
    </item>
  </channel>
</rss>

