<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect authentication happened twice while LDAP  and Okta Auth in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559400#M4427</link>
    <description>&lt;P&gt;auth_method is saml.&lt;BR /&gt;Authentication is happens successful but our users issue is Okta-auth prompt appears twice.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2023 18:26:41 GMT</pubDate>
    <dc:creator>tthapa23</dc:creator>
    <dc:date>2023-09-25T18:26:41Z</dc:date>
    <item>
      <title>Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559392#M4425</link>
      <description>&lt;P&gt;Recently we moved&amp;nbsp; to PA-3410 software version&amp;nbsp;&lt;SPAN&gt;11.0.1-h2 from&amp;nbsp;PA-850&amp;nbsp; software version 10.2.3-h4 .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on both firewalls&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="label"&gt;GlobalProtect Agent&lt;/TD&gt;
&lt;TD class="data"&gt;6.1.1&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have selected option for authentication override&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Portals&lt;BR /&gt;Generate cookie for authentication override&lt;/P&gt;
&lt;P&gt;on Gateway &lt;BR /&gt;Accept cookie for authentication override&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcases.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY" target="_blank" rel="noopener"&gt;https://supportcases.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000boODCAY&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It was working perfectly fine with single okta prompt on PA-850 but after moving onto the&amp;nbsp; PA-3410 GP okta auth prompts twice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As PAN TAC has suggested cleared GP and Laptop web browser cache.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Try clearing the Browser cache and Cache file by referring below document.&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/clearing-globalprotect-cookies/td-p/354097" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-discussions/clearing-globalprotect-cookies/td-p/354097&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. How to uninstall GlobalProtect Agent software completely in Windows&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNGHCA2" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNGHCA2&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Uninstall the GlobalProtect App for macOS&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-mac/uninstall-the-globalprotect-app-for-mac" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-user-guide/globalprotect-app-for-mac/uninstall-the-globalprotect-app-for-mac&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Form the firewall, there is a method to clear the cache of GlobalProtect for Connected users by imposing the below commands. (This might prevent you from uninstalling it on each user if it works).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show global-protect-gateway current-user (To check connected users)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; clear user-cache all type GP ( To delete the cache for connected users).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;After doing everything above mentioned, still GP Okta auth prompts twice.&amp;nbsp; is there anyone have solutions and suggestion for this issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 17:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559392#M4425</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-25T17:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559399#M4426</link>
      <description>&lt;P&gt;Monitor &amp;gt; Logs &amp;gt; GlobalProtect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Filter:&lt;/P&gt;
&lt;P&gt;( eventid eq 'portal-auth' ) or ( eventid eq 'gateway-auth' )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add "Auth Method" and "Error" columns.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What auth methods and errors you see?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 17:58:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559399#M4426</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-25T17:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559400#M4427</link>
      <description>&lt;P&gt;auth_method is saml.&lt;BR /&gt;Authentication is happens successful but our users issue is Okta-auth prompt appears twice.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 18:26:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559400#M4427</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-25T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559401#M4428</link>
      <description />
      <pubDate>Mon, 25 Sep 2023 18:27:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559401#M4428</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-25T18:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559403#M4429</link>
      <description>&lt;P&gt;Please ignore first attachment. second logs event is which i tried login back GP.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 18:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559403#M4429</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-25T18:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559407#M4430</link>
      <description>&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client connects to portal.&lt;/P&gt;
&lt;P&gt;Tries cookie.&lt;/P&gt;
&lt;P&gt;Cookie is expired so uses "auth-sequence" to log in.&lt;/P&gt;
&lt;P&gt;Portal generates new cookie for user.&lt;/P&gt;
&lt;P&gt;Login to gateway uses new cookie and succeeds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1695667815773.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53977iD7DF9AF22BFE9B23/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1695667815773.png" alt="Raido_Rattameister_1-1695667815773.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your log screenshot don't reveal what is happening on your side during same process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 18:54:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559407#M4430</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-25T18:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559408#M4431</link>
      <description>&lt;P&gt;Error says user is not in allow list.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 19:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559408#M4431</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-25T19:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559436#M4433</link>
      <description>&lt;P&gt;I think it is better for you to go back to TAC with this info - user is not in allowlist when using cookies and let them figure out.&lt;/P&gt;
&lt;P&gt;Without seeing more details it is hard to troubleshoot further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try to set allowlist to "all" under auth profile (Device &amp;gt; Authentication Profile &amp;gt; &lt;EM&gt;Auth-Profile-Name&lt;/EM&gt;&amp;nbsp;&amp;gt; Advanced tab) and test if it starts working and go from there.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 06:17:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559436#M4433</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-26T06:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect authentication happened twice while LDAP  and Okta Auth</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559592#M4437</link>
      <description>&lt;P&gt;Hi Raido_Rattameister,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thank you for your prompt replies and suggestions.&lt;BR /&gt;Its was working perfectly fine , when we upgraded PA-3410 from&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="label"&gt;Software Version&lt;/TD&gt;
&lt;TD class="data"&gt;10.2.3-h4&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;to&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="label"&gt;Software Version&lt;/TD&gt;
&lt;TD class="data"&gt;11.0.1-h2&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;PAN TAC came back with answer " Its KNOWN Bug on this Software Version 11.0.1-h2".&amp;nbsp; They asked us to test the below scenario&amp;nbsp;&lt;BR /&gt;1. Remove generate cookie from the portal.&lt;BR /&gt;2. Generate and accept cookies at the gateway only.&lt;BR /&gt;&lt;BR /&gt;The above scenario will trigger the SAML redirect during the first login and from 2nd login, it will trigger a redirect to SAML only for the portal and the gateway will login as per cookie. After changing above suggested options it started working with single SAML Okta auth&amp;nbsp; prompt but its temporary workaround. They are working on permanent hotfix solution on this version. I will keep updated here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 03:30:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-authentication-happened-twice-while-ldap-and-okta/m-p/559592#M4437</guid>
      <dc:creator>tthapa23</dc:creator>
      <dc:date>2023-09-27T03:30:25Z</dc:date>
    </item>
  </channel>
</rss>

