<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect MFA with Kerberos and RSA in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-kerberos-and-rsa/m-p/470647#M2545</link>
    <description>&lt;P&gt;Hello everyone, Palo Alto noobie here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure GlobalProtect VPN with MFA authentication using Kerberos authentication protocol against AD and RSA hard tokens.&lt;BR /&gt;I have configured the GlobalProtect portal and gateway using different loopbacks. For the portal authentication I am using only Kerberos while for the gateway authentication I intent to use MFA (Kerberos + RSA)&lt;/P&gt;&lt;P&gt;In order to configure MFA for the VPN gateway I did the following:&lt;/P&gt;&lt;P&gt;1. Created MFA server Profile with MFA Vendor: RSA SecurID Access&lt;/P&gt;&lt;P&gt;2. Linked the MFA server profile to the Authentication profile: Authentication: Kerberos Server profile, Factors: MFA server profile&lt;/P&gt;&lt;P&gt;3. Enabled Captive Profile with the authentication profile described above, and redirect host uses the same loopback as&amp;nbsp;GlobalProtect portal.&lt;/P&gt;&lt;P&gt;4. Created interface management with response pages and user-ID&lt;/P&gt;&lt;P&gt;5. Linked&amp;nbsp;interface management profile with the loopback used for&amp;nbsp;GlobalProtect portal and captive portal&lt;/P&gt;&lt;P&gt;6. In the zone where&amp;nbsp;GlobalProtect portal and captive portal are assigned, User_ID is enabled&lt;/P&gt;&lt;P&gt;7. Created new Autentication object: Authentcation Method:web-form Authentication Profile: one created in bullet 2&lt;/P&gt;&lt;P&gt;8. Created Authentication Policy: defining just source and destination zone, leaving service to any and assigning authentication enforcement to the one created in bullet 8.&lt;/P&gt;&lt;P&gt;9. Under GlobalProtect portal Configuration for the authentication using kerberos profile&lt;/P&gt;&lt;P&gt;10. Under GlobalProtect Portal Configuration under agent config:&lt;/P&gt;&lt;P&gt;- authentication: components that require 2FA: internal gw and external gw are checked&lt;/P&gt;&lt;P&gt;-app: Use SSO (win): NO,&lt;/P&gt;&lt;P&gt;-app: Enable inbound authentication prompts from MFA gw: YES&lt;/P&gt;&lt;P&gt;-app: Trusted MFA GW: IP of the RSA server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After installing the GlobalProtect client from the&amp;nbsp;Configuration Portal the situation is following:&lt;/P&gt;&lt;P&gt;- after entering the&amp;nbsp;&amp;nbsp;Configuration Portal IP I am prompted to logon&lt;/P&gt;&lt;P&gt;- after the portal logon is successful I am prompted to authenticate on the&amp;nbsp;Configuration Portal gateway after entering the username and password I am connected. No prompts for the second factor authentication and no captive portal is opening but it's connecting successfully.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Anyone had the similar issue?&lt;/P&gt;&lt;P&gt;Any advice would be highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 05 Mar 2022 02:43:26 GMT</pubDate>
    <dc:creator>netgirl</dc:creator>
    <dc:date>2022-03-05T02:43:26Z</dc:date>
    <item>
      <title>GlobalProtect MFA with Kerberos and RSA</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-kerberos-and-rsa/m-p/470647#M2545</link>
      <description>&lt;P&gt;Hello everyone, Palo Alto noobie here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure GlobalProtect VPN with MFA authentication using Kerberos authentication protocol against AD and RSA hard tokens.&lt;BR /&gt;I have configured the GlobalProtect portal and gateway using different loopbacks. For the portal authentication I am using only Kerberos while for the gateway authentication I intent to use MFA (Kerberos + RSA)&lt;/P&gt;&lt;P&gt;In order to configure MFA for the VPN gateway I did the following:&lt;/P&gt;&lt;P&gt;1. Created MFA server Profile with MFA Vendor: RSA SecurID Access&lt;/P&gt;&lt;P&gt;2. Linked the MFA server profile to the Authentication profile: Authentication: Kerberos Server profile, Factors: MFA server profile&lt;/P&gt;&lt;P&gt;3. Enabled Captive Profile with the authentication profile described above, and redirect host uses the same loopback as&amp;nbsp;GlobalProtect portal.&lt;/P&gt;&lt;P&gt;4. Created interface management with response pages and user-ID&lt;/P&gt;&lt;P&gt;5. Linked&amp;nbsp;interface management profile with the loopback used for&amp;nbsp;GlobalProtect portal and captive portal&lt;/P&gt;&lt;P&gt;6. In the zone where&amp;nbsp;GlobalProtect portal and captive portal are assigned, User_ID is enabled&lt;/P&gt;&lt;P&gt;7. Created new Autentication object: Authentcation Method:web-form Authentication Profile: one created in bullet 2&lt;/P&gt;&lt;P&gt;8. Created Authentication Policy: defining just source and destination zone, leaving service to any and assigning authentication enforcement to the one created in bullet 8.&lt;/P&gt;&lt;P&gt;9. Under GlobalProtect portal Configuration for the authentication using kerberos profile&lt;/P&gt;&lt;P&gt;10. Under GlobalProtect Portal Configuration under agent config:&lt;/P&gt;&lt;P&gt;- authentication: components that require 2FA: internal gw and external gw are checked&lt;/P&gt;&lt;P&gt;-app: Use SSO (win): NO,&lt;/P&gt;&lt;P&gt;-app: Enable inbound authentication prompts from MFA gw: YES&lt;/P&gt;&lt;P&gt;-app: Trusted MFA GW: IP of the RSA server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After installing the GlobalProtect client from the&amp;nbsp;Configuration Portal the situation is following:&lt;/P&gt;&lt;P&gt;- after entering the&amp;nbsp;&amp;nbsp;Configuration Portal IP I am prompted to logon&lt;/P&gt;&lt;P&gt;- after the portal logon is successful I am prompted to authenticate on the&amp;nbsp;Configuration Portal gateway after entering the username and password I am connected. No prompts for the second factor authentication and no captive portal is opening but it's connecting successfully.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Anyone had the similar issue?&lt;/P&gt;&lt;P&gt;Any advice would be highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 05 Mar 2022 02:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-mfa-with-kerberos-and-rsa/m-p/470647#M2545</guid>
      <dc:creator>netgirl</dc:creator>
      <dc:date>2022-03-05T02:43:26Z</dc:date>
    </item>
  </channel>
</rss>

