<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect two MFA prompts for Portal and Gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590643#M5516</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159288"&gt;@vsurresh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An authentication cookie is created on your device - very similar to the browser authentication cookie used for this community.&amp;nbsp; Some times you have to enter your username and password, and sometimes the browser detects the cookie and you login without being prompted for credentials.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting the portal to &lt;EM&gt;generate&lt;/EM&gt; the cookie means that it will require username/password/MFA every time.&amp;nbsp; Setting the gateway to &lt;EM&gt;accept&lt;/EM&gt; the cookie means that after the portal generates it, the user can login to the gateway without being prompted.&amp;nbsp; (On a side note, even without MFA the portal caches the username and password and forwards it to the gateway.)&amp;nbsp; If the portal only generates the cookie, the lifetime is not as critical.&amp;nbsp; Two minutes probably should be fine.&amp;nbsp; If the portal and gateway both accepted the cookie, the user could connect/disconnect/connect again within the lifetime and not have to enter credentials or use MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is also good to know that some IdPs such as Entra use their own authentication cookies where you do not have to set those options on the portal or gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 23:07:39 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-06-27T23:07:39Z</dc:date>
    <item>
      <title>Global Protect two MFA prompts for Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590642#M5515</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to understand the difference between 'Generate cookie for authentication override' and 'Accept cookie for authentication override' on both portals and gateways. I went through all the official guides but still can't seem to understand. Suppose we have MFA set up for both the portal and the gateway. Every time someone tries to connect to GP, there will be two MFA prompts. The guide says I need to tick the first box on the portal and the second box on the gateway. But what cookie lifetime should we use? Should we set it to around 2 minutes so the first MFA will be valid for the next two minutes, and within this time, the gateway authentication will succeed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the guide -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LvbCAE&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004LvbCAE&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The screenshot shows 24 hour for the gateway cookie life time, what does that mean? TIA&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 21:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590642#M5515</guid>
      <dc:creator>vsurresh</dc:creator>
      <dc:date>2024-06-27T21:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect two MFA prompts for Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590643#M5516</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159288"&gt;@vsurresh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;An authentication cookie is created on your device - very similar to the browser authentication cookie used for this community.&amp;nbsp; Some times you have to enter your username and password, and sometimes the browser detects the cookie and you login without being prompted for credentials.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setting the portal to &lt;EM&gt;generate&lt;/EM&gt; the cookie means that it will require username/password/MFA every time.&amp;nbsp; Setting the gateway to &lt;EM&gt;accept&lt;/EM&gt; the cookie means that after the portal generates it, the user can login to the gateway without being prompted.&amp;nbsp; (On a side note, even without MFA the portal caches the username and password and forwards it to the gateway.)&amp;nbsp; If the portal only generates the cookie, the lifetime is not as critical.&amp;nbsp; Two minutes probably should be fine.&amp;nbsp; If the portal and gateway both accepted the cookie, the user could connect/disconnect/connect again within the lifetime and not have to enter credentials or use MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is also good to know that some IdPs such as Entra use their own authentication cookies where you do not have to set those options on the portal or gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 23:07:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590643#M5516</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-06-27T23:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect two MFA prompts for Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590747#M5519</link>
      <description>&lt;P&gt;Thank you for the response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"Setting the gateway to accept the cookie means that after the portal generates it, the user can login to the gateway without being prompted."&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here, am I right in thinking that, when we set the lifetime to 2 minutes and the gateway, if the cookie portal generated is more than 2 minutes for example, then the gateway don't accept it? TIA&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jun 2024 20:00:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590747#M5519</guid>
      <dc:creator>vsurresh</dc:creator>
      <dc:date>2024-06-29T20:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect two MFA prompts for Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590772#M5521</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/159288"&gt;@vsurresh&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is correct.&amp;nbsp; I can't think of any scenario where the GP client would take longer than 2 minutes after authenticating in the portal to authenticate to the gateway.&amp;nbsp; You can also set it higher if you are concerned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 21:35:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-two-mfa-prompts-for-portal-and-gateway/m-p/590772#M5521</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-06-30T21:35:16Z</dc:date>
    </item>
  </channel>
</rss>

