<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Host certificate check HIP objects configuration in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556314#M4352</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67640"&gt;@FranklinV&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the Client Authentication config, you can choose certificate only or certificate and username/password.&amp;nbsp; The username/password can reference many Authentication Profile types including SAML.&amp;nbsp; MFA can be built into many authentication methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1693793520839.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53411i68C145EC4CC72A08/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1693793520839.png" alt="TomYoung_0-1693793520839.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Sep 2023 02:14:34 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-09-04T02:14:34Z</dc:date>
    <item>
      <title>Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/555826#M4336</link>
      <description>&lt;P&gt;we are planning to configure certificate check HIP object&amp;nbsp; and authentication based on that. we are not getting any clear picture in online or palo alto portal. please help up to provide resource...&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 09:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/555826#M4336</guid>
      <dc:creator>ngd-netsec</dc:creator>
      <dc:date>2023-08-30T09:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/555841#M4338</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/199141"&gt;@ngd-netsec&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can configure GlobalProtect to authenticate the client with a certificate and/or username/password.&amp;nbsp; You do not have to configure HIP checks.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIICA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIICA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also Google "globalprotect client certificate authentication" and you will find more docs and videos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured GP certificate authentication for a few of my customers, and it is easy once you get the hang of it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 12:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/555841#M4338</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-08-30T12:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556309#M4351</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you configure CBA for customers, do you use a second factor i.e., SAML/MFA? or CBA is the only factor?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 01:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556309#M4351</guid>
      <dc:creator>FranklinV</dc:creator>
      <dc:date>2023-09-04T01:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556314#M4352</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67640"&gt;@FranklinV&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the Client Authentication config, you can choose certificate only or certificate and username/password.&amp;nbsp; The username/password can reference many Authentication Profile types including SAML.&amp;nbsp; MFA can be built into many authentication methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1693793520839.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53411i68C145EC4CC72A08/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1693793520839.png" alt="TomYoung_0-1693793520839.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 02:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556314#M4352</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-04T02:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556319#M4353</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;thanks! I am familiar with this setting. Was just curious to know if others are okay with a single factor (CBA only).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW - would you know if when CBA and username/password are configured with SAML (+built in MFA) as the second factor, would users receive the SAML prompt for the second factor (username/password) or the MFA prompt?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As an example: First factor is certificate, Second factor MFA (no username/password).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 03:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556319#M4353</guid>
      <dc:creator>FranklinV</dc:creator>
      <dc:date>2023-09-04T03:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Host certificate check HIP objects configuration</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556371#M4355</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/67640"&gt;@FranklinV&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got it!&amp;nbsp; I understand your question now.&amp;nbsp; I do not configure Certificate Based Authentication only.&amp;nbsp; It is recommended to use 2FA for GlobalProtect (RA VPN) because if you use one factor and it is compromised, then threats have access to your network.&amp;nbsp; RA VPN is a commonly exploited means of gaining access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regard to SAML+MFA without a u/p prompt, I know the portal can be configured to accept authentication cookies, but I have never configured it or seen it on the 1st login.&amp;nbsp; GP also can use HW/SW tokens, although I have not seen a lot of documentation on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another possibility is to use RADIUS/EAP-TLS and have the RADIUS server extract the username from the certificate and communicate with the MFA software.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 09:35:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/host-certificate-check-hip-objects-configuration/m-p/556371#M4355</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-04T09:35:52Z</dc:date>
    </item>
  </channel>
</rss>

