<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Authentication Override in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516402#M3206</link>
    <description>&lt;P&gt;Hi Adrian, many thanks for your reply, yes it has expired.. but it has expired on the portal and 6 gateways yet one of the gateways is still accepting the override. This has same settings as all the other 5 gateways that are failing…&lt;/P&gt;</description>
    <pubDate>Thu, 29 Sep 2022 20:05:11 GMT</pubDate>
    <dc:creator>Mick.Ball</dc:creator>
    <dc:date>2022-09-29T20:05:11Z</dc:date>
    <item>
      <title>GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516209#M3199</link>
      <description>&lt;P&gt;Been using Radius auth to portal with auth override to gateway for years but seems to now be playing up...&amp;nbsp; Gateway is requesting radius auth and ignoring override settings.&lt;/P&gt;
&lt;P&gt;This is the same issue on both Windoze and IOS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA 3020&amp;nbsp;&amp;nbsp;9.1.14&lt;/P&gt;
&lt;P&gt;We have no custom checks, just Radius auth (which is working fine)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks in advance...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516209#M3199</guid>
      <dc:creator>Mick.Ball</dc:creator>
      <dc:date>2022-09-28T09:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516401#M3205</link>
      <description>&lt;P&gt;Override using a cookie signed on the Portal and accepted on the Gateway? Has the certificate used to encrypt/decrypt the cookie possibly expired?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 19:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516401#M3205</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-29T19:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516402#M3206</link>
      <description>&lt;P&gt;Hi Adrian, many thanks for your reply, yes it has expired.. but it has expired on the portal and 6 gateways yet one of the gateways is still accepting the override. This has same settings as all the other 5 gateways that are failing…&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 20:05:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516402#M3206</guid>
      <dc:creator>Mick.Ball</dc:creator>
      <dc:date>2022-09-29T20:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516405#M3208</link>
      <description>&lt;P&gt;How long ago has the cert expired vs. your cookie lifetime? I would think signing a cookie with an expired cert should fail... it is no longer valid after all, but a cookie that was signed before the cert expired might still be valid until the cookie expires.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look in the logs for the accepted/rejected cookie status. I am not running cookies to auth any longer but when I was the cookie status would show up in the description/error field. It was either in the System logs "( subtype eq auth )" or the GlobalProtect logs "( ( eventid eq gateway-prelogin ) or ( eventid eq gateway-auth ) )", I can't recall.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 20:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516405#M3208</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-29T20:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516453#M3210</link>
      <description>&lt;P&gt;The certificate expired years ago, it just seems to use the keys for cookie encrypt/decrypt.&lt;/P&gt;
&lt;P&gt;I have added a new cert and portal/gateway on one of the failing devices and still no good.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there are no errors in pa or gp logs. The log output for both is the same if you remove the option to accept cookies.. it just prompts for OTP. &amp;nbsp;It seems to ignore the accept option but it shows as selected when you do show gateway…… on cli.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 07:33:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516453#M3210</guid>
      <dc:creator>Mick.Ball</dc:creator>
      <dc:date>2022-09-30T07:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516485#M3213</link>
      <description>&lt;P&gt;The only other thing I can think of at the moment is that the firewall and/or client clocks are way out. Are you using NTP/etc. to keep clocks synced to a common time?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 16:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516485#M3213</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-30T16:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Authentication Override</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516490#M3214</link>
      <description>&lt;P&gt;Thanks again for your help Adrian, that was one of the first things I looked into as had a similar issue years ago. We do use NTP and cli time check and dashboard show time is spot on….&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have logged a call with our palo support and they are also struggling for a reason/solution. I’m going to bounce one of the gateways tonight as been up for 135 days…. &amp;nbsp;Clutching at straws but you never know, thanks again for your time.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 16:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-authentication-override/m-p/516490#M3214</guid>
      <dc:creator>Mick.Ball</dc:creator>
      <dc:date>2022-09-30T16:50:03Z</dc:date>
    </item>
  </channel>
</rss>

