<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect SAML Okta groups integration in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-okta-groups-integration/m-p/508674#M2980</link>
    <description>&lt;P&gt;Nevermind figured it out. Looks like I needed LDAP.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 18:17:34 GMT</pubDate>
    <dc:creator>sirons</dc:creator>
    <dc:date>2022-07-13T18:17:34Z</dc:date>
    <item>
      <title>Global Protect SAML Okta groups integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-okta-groups-integration/m-p/508579#M2977</link>
      <description>&lt;P&gt;I'm currently working on setting up our 2 PAs for VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to get the configuration set up to do something similar to what we had on Cisco but with PA and SAML instead of LDAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've followed this doc&amp;nbsp;&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html" target="_blank"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.html&lt;/A&gt;&amp;nbsp;but in section 8 it doesn't exactly specify how to do that. I have 2 groups called vpn_level_1 and vpn_level_2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These groups would differentiate between which Client IP subnet as they'd reach different resources in the on prem network. Example 10.0.1.0/24 would be for vpn_level_1 and 10.0.2.0/24 would be for vpn_level_2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our Okta instance sync's our AD groups and I'm trying not to do LDAP with this if at all possible. I also couldn't find a feature in the Gateway &amp;gt; Agent &amp;gt; Client Settings where IP Addressing would be on a specific group condition.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I couldn't find this specific situation in the forums so any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 17:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-okta-groups-integration/m-p/508579#M2977</guid>
      <dc:creator>sirons</dc:creator>
      <dc:date>2022-07-12T17:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SAML Okta groups integration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-okta-groups-integration/m-p/508674#M2980</link>
      <description>&lt;P&gt;Nevermind figured it out. Looks like I needed LDAP.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 18:17:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-okta-groups-integration/m-p/508674#M2980</guid>
      <dc:creator>sirons</dc:creator>
      <dc:date>2022-07-13T18:17:34Z</dc:date>
    </item>
  </channel>
</rss>

