<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220426#M6469</link>
    <description>&lt;P&gt;the accept cookie has a time set currently of 30 minutes. &lt;/P&gt;
&lt;P&gt;regarding global protect version on windows machines I've tested with a few number of versions, all have the same issue: 6.1.1, 6.2.3, 6.2.7&lt;/P&gt;
&lt;P&gt;the firewall itself is currently running version 10.1.13&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2025 07:29:02 GMT</pubDate>
    <dc:creator>TommieVanHove</dc:creator>
    <dc:date>2025-02-14T07:29:02Z</dc:date>
    <item>
      <title>Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220385#M6467</link>
      <description>&lt;P&gt;Hello. &lt;BR /&gt;&lt;BR /&gt;so I have a strange issue. &lt;BR /&gt;&lt;BR /&gt;for a setup we have a gp portal and gateway configured. &lt;BR /&gt;the authentication to both is an auth profile or sequence that involves sending a username and OTP token code to a radius server. &lt;BR /&gt;the user has to enter both 1 otp for the portal login and then a differnt otp for the gateway login. &lt;BR /&gt;&lt;BR /&gt;I understood enabling "generate auth cookie" on the portal and "accept auth cookie" on the gateway should prevent the double OTP requirement. &lt;BR /&gt;However this does not seem to work at all. no matter what I configure I always have to provide 2 otp when I log in. &lt;BR /&gt;&lt;BR /&gt;I enter the portal OTP, I briefly see: retrieving portal config, then find the best possible gateway and then get prompted for a 2nd otp. &lt;BR /&gt;&lt;BR /&gt;on the firewall all these settings have been set: &lt;BR /&gt;generate auth cookie on the portal. &lt;BR /&gt;accept auth cookie on the gateway (using the same cert as the generate on portal&lt;BR /&gt;sso on windows has been set to no as the user logged in name on the laptop is not the same as the gp username. &lt;BR /&gt;save username has been set in the portal. &lt;BR /&gt;on the portal I have tried with all possible combinations of components requiring dynamic credentials on or off. no difference. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;in the globalprotect logs on the firewall I see entries with event: portal-gen-cookie. &lt;BR /&gt;but afterwards I don't see that cookie getting used/presented anywhere. &lt;BR /&gt;in system logs only auth events are seen with auth protocol "chap" towards the radius, never one with auth protocol cookie. &lt;BR /&gt;&lt;BR /&gt;when collecting pangps logs I think this is where the issue is but no idea why: &lt;BR /&gt;I think the cookie is created here: &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(P6488-T10648)Debug( 169): 02/13/25 18:33:35:780 profileInfo username "john", profile path (null), server (null)
(P6488-T10648)Debug(2925): 02/13/25 18:33:35:786 Serialized portal user auth cookie to file C:\Users\"john"\AppData\Local\Palo Alto Networks\GlobalProtect\PanPUAC_"cookiefile".dat. 246 bytes.
(P6488-T10648)Debug(2710): 02/13/25 18:33:35:787 Serialize empty cookie for portal "portalurl" and pre-logon user
(P6488-T10648)Debug(2717): 02/13/25 18:33:35:788 SerializePortalPrelogonAuthCookie to file PanPPAC_"cookiefile2".dat
(P6488-T10648)Debug(10162): 02/13/25 18:33:35:788 Retrieved pre-logon-tunnel-rename-timeout value -1
(P6488-T10648)Debug(10170): 02/13/25 18:33:35:788 Retrieved user-switch-tunnel-rename-timeout value 0&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;and a bit later it seems the gateway doesn't find this? &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(P6488-T20992)Debug(4101): 02/13/25 18:33:36:165 ----Gateway Login starts----
(P6488-T20992)Debug(13999): 02/13/25 18:33:36:165 Set to service bUseCCUserGateway 0 and ccUserNameGateway 
(P6488-T20992)Debug(2182): 02/13/25 18:33:36:165 Update user name from  to "john"
(P6488-T20992)Debug(6396): 02/13/25 18:33:36:165 OtpSaveCredential is save_username
(P6488-T20992)Debug(6434): 02/13/25 18:33:36:165 External network gateway without OTP authentication
(P6488-T20992)Debug(6497): 02/13/25 18:33:36:165 Need to prompt user enter gateway credential. Set dpgc to true.
(P6488-T20992)Debug(  41): 02/13/25 18:33:36:166 Roaming profile is false
(P6488-T20992)Debug( 169): 02/13/25 18:33:36:173 profileInfo username "john", profile path (null), server (null)
(P6488-T20992)Debug(2813): 02/13/25 18:33:36:176 Unserialized empty cookie for portal "portalurl" and user "john"
(P6488-T20992)Debug(2742): 02/13/25 18:33:36:176 Unserialized empty cookie for portal "portalurl" and pre-logon user.
(P6488-T20992)Debug(4167): 02/13/25 18:33:36:176 bIsEmptyUser is 0, bDPGCforManualOnlyGateway is 0, bDPGCNotforManualOnlyGateway is 0
(P6488-T20992)Debug(4172): 02/13/25 18:33:36:176 Collect user credential for gateway "portalurl" username "john", ccUsername , IsExtDPGC 0, IsIntDPGC 0, IsManualOnlyGateway 0, not connecting to manual gateway
(P6488-T20992)Debug(4183): 02/13/25 18:33:36:176 Gateway user "john"
(P6488-T20992)Debug(6853): 02/13/25 18:33:36:176 Gateway auth method: credential, auth src: (null)&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 17:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220385#M6467</guid>
      <dc:creator>TommieVanHove</dc:creator>
      <dc:date>2025-02-13T17:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220390#M6468</link>
      <description>&lt;P&gt;How many minutes old cookie your gateway accepts as valid?&lt;/P&gt;
&lt;P&gt;What PANOS and GP agent version are you running? (There have been some bugs in the past that caused 2x OTP even with correct config).&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 18:43:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220390#M6468</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-02-13T18:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220426#M6469</link>
      <description>&lt;P&gt;the accept cookie has a time set currently of 30 minutes. &lt;/P&gt;
&lt;P&gt;regarding global protect version on windows machines I've tested with a few number of versions, all have the same issue: 6.1.1, 6.2.3, 6.2.7&lt;/P&gt;
&lt;P&gt;the firewall itself is currently running version 10.1.13&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 07:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220426#M6469</guid>
      <dc:creator>TommieVanHove</dc:creator>
      <dc:date>2025-02-14T07:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220446#M6470</link>
      <description>&lt;P&gt;Monitor &amp;gt; Logs &amp;gt; GlobalProtect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is portal-gen-cookie success?&lt;/P&gt;
&lt;P&gt;Does gateway-auth try to use Cookie as auth method?&lt;/P&gt;
&lt;P&gt;If it does and fails then what does ERROR column say about failure reason?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_1-1739542218524.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66046i91B837B5FD9588FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_1-1739542218524.png" alt="Raido_Rattameister_1-1739542218524.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 14:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220446#M6470</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-02-14T14:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220451#M6471</link>
      <description>&lt;P&gt;That is just the strange thing. &lt;BR /&gt;&lt;BR /&gt;I do see portal-gen-cookie. &lt;BR /&gt;attached screenshot is when I also activated generate cookie on the gateway so I even see gateway-gen-cookie. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;but afterwards I don't see any attempts or errors trying to use a cookie which makes me think the error is somewhere on the gp client/clientside in providing or looking up the generated cookie.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gencookie.PNG" style="width: 799px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66050iD31B01ABC734F965/image-size/large?v=v2&amp;amp;px=999" role="button" title="gencookie.PNG" alt="gencookie.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 14:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220451#M6471</guid>
      <dc:creator>TommieVanHove</dc:creator>
      <dc:date>2025-02-14T14:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220453#M6472</link>
      <description>&lt;P&gt;If you look at GP release notes and search for "cookie" you see many different bugs over times (&lt;A href="https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/globalprotect-addressed-issues" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/6-2/globalprotect-app-release-notes/globalprotect-addressed-issues&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to log out from GlobalProtect on agent Settings page and log in again.&lt;/P&gt;
&lt;P&gt;If this does not fix it then open case with support to analyze.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 14:46:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1220453#M6472</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-02-14T14:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect login using OTP (radius server) keeps asking one OTP for both portal and gateway despite auth override configured</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1223548#M6568</link>
      <description>&lt;P&gt;It took some time and afterwards I forgot to come back here and mark you answer as solution. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but there was indeed a bug in that panos version 10.1.13:&lt;BR /&gt;&lt;SPAN&gt; PAN-248651 - Fixed a GlobalProtect issue that prevented the firewall from sending authentication cookies.&lt;BR /&gt;and the fix versions are&lt;BR /&gt;10.1.14, 10.1.13-h1.&lt;BR /&gt;&lt;BR /&gt;so despite the firewall logs showing that a cookie was generated on the firewall it seems it is never sent correctly to the client. which also explains the GPA logs regarding an Empty cookie and the issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 09:00:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-login-using-otp-radius-server-keeps-asking-one-otp/m-p/1223548#M6568</guid>
      <dc:creator>TommieVanHove</dc:creator>
      <dc:date>2025-03-12T09:00:13Z</dc:date>
    </item>
  </channel>
</rss>

