<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect User Login in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644097#M6150</link>
    <description>&lt;P&gt;Disable Authentication Override by removing the generating and accepting of cookie auth under Portal and Gateway.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2024 14:35:15 GMT</pubDate>
    <dc:creator>J8Lake</dc:creator>
    <dc:date>2024-11-21T14:35:15Z</dc:date>
    <item>
      <title>Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/640050#M6140</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to control the Global Protect login?&amp;nbsp; &amp;nbsp;I want to have when a user disconnects from GP, the next time user logs in they get prompted for MFA.&amp;nbsp; &amp;nbsp;As of now, seems user can disconnect/reconnect repeatedly thru out the day and never get prompted with MFA.&amp;nbsp; &amp;nbsp;How/where do I fix this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 15:02:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/640050#M6140</guid>
      <dc:creator>rcraxton</dc:creator>
      <dc:date>2024-11-20T15:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641077#M6141</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/333499"&gt;@rcraxton&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your issue is typically an authentication cookie configuration.&amp;nbsp; The solution can be different for different vendors.&amp;nbsp; What MFA product are you using?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 00:35:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641077#M6141</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-11-21T00:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641114#M6142</link>
      <description>&lt;P&gt;Hello Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure how a cookie come into play, but if you have information?&amp;nbsp; &amp;nbsp;We use DUO.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 00:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641114#M6142</guid>
      <dc:creator>rcraxton</dc:creator>
      <dc:date>2024-11-21T00:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641141#M6143</link>
      <description>&lt;P&gt;The Portal and Gateway config each has an option to generate and/or accept an authentication cookie. The configuration is on both the portal and gateway under authentication override. Its having and passing the token for authentication. You can encrypt the cookie with a certificate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cookies are named&amp;nbsp;PanPUAC_*.dat and located in&amp;nbsp;&lt;SPAN&gt;C:\Users\%USERNAME%\AppData\Local\Palo Alto Networks\GlobalProtect&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 01:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/641141#M6143</guid>
      <dc:creator>J8Lake</dc:creator>
      <dc:date>2024-11-21T01:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643959#M6147</link>
      <description>&lt;P&gt;Everything I read appears to put a time limit on the user - then when this limit is reached, user gets kicked out &amp;lt;--- Not what I want.&lt;/P&gt;
&lt;P&gt;Looking for way to allow user to login and work, but if they happen to disconnect Global Protect, shut down or reboot machine on next GP connection to our network are prompted by DUO MFA to allow login.&amp;nbsp; &amp;nbsp;Currently, users have roughly a day of not getting prompted by DUO for MFA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 13:24:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643959#M6147</guid>
      <dc:creator>rcraxton</dc:creator>
      <dc:date>2024-11-21T13:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643986#M6148</link>
      <description>&lt;P&gt;Yes, there are timers associated with the cookie validity. So that would be expected behavior with cookies enabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 13:38:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643986#M6148</guid>
      <dc:creator>J8Lake</dc:creator>
      <dc:date>2024-11-21T13:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643989#M6149</link>
      <description>&lt;P&gt;So how do I get to where I want to be?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Rich&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 13:42:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/643989#M6149</guid>
      <dc:creator>rcraxton</dc:creator>
      <dc:date>2024-11-21T13:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644097#M6150</link>
      <description>&lt;P&gt;Disable Authentication Override by removing the generating and accepting of cookie auth under Portal and Gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 14:35:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644097#M6150</guid>
      <dc:creator>J8Lake</dc:creator>
      <dc:date>2024-11-21T14:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644137#M6151</link>
      <description>&lt;P&gt;So by disabling the Authentication Override, this will give what I'm looking for?&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 14:53:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644137#M6151</guid>
      <dc:creator>rcraxton</dc:creator>
      <dc:date>2024-11-21T14:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644164#M6152</link>
      <description>&lt;P&gt;Yes, the described behavior would be inline with have Cookie Auth enabled to generate and accept on both Portal and Gateway. Removing those configurations should require users to enter their creds to reconnect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 15:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/644164#M6152</guid>
      <dc:creator>J8Lake</dc:creator>
      <dc:date>2024-11-21T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/645065#M6155</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/333499"&gt;@rcraxton&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218280"&gt;@J8Lake&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you disable authentication cookies, your users will have to MFA twice - one for the portal and one for the gateway.&amp;nbsp; That may be acceptable, but if you only want them to MFA once, then you can enable authentication cookies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.duo.com/s/article/2054?language=en_US" target="_blank"&gt;https://help.duo.com/s/article/2054?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can set the cookie lifetime to a short interval, like a couple minutes.&amp;nbsp; And after the interval expires, the user will NOT be logged out. The cookie is local like a browser cookie that bypasses the need for MFA.&amp;nbsp; It only is used when the user logs out and back in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 22:36:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/645065#M6155</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-11-21T22:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/650391#M6158</link>
      <description>&lt;P&gt;Yes, good catch and point. Thanks Tom. You could also disable accept on just the Portal and then they would have to reauth everytime, but just once.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 22:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-login/m-p/650391#M6158</guid>
      <dc:creator>J8Lake</dc:creator>
      <dc:date>2024-11-22T22:15:25Z</dc:date>
    </item>
  </channel>
</rss>

