<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local and SAML  users authentication on the single GP Portal and Gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1220950#M6478</link>
    <description>&lt;P&gt;I have a task to use 2 authentication methods - local and SAML&amp;nbsp;on the single GP Portal and Gateway. First check local users and if username not found then check SAML users. As I know authentication sequence isn't supported for&amp;nbsp;SAML. Separating users by OS type isn't way for us because different users (SAML and local) can use the same OS type. Are there any ways to do this task on single firewall?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2025 16:18:52 GMT</pubDate>
    <dc:creator>Dmytro-Ostapenko</dc:creator>
    <dc:date>2025-02-19T16:18:52Z</dc:date>
    <item>
      <title>Local and SAML  users authentication on the single GP Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1220950#M6478</link>
      <description>&lt;P&gt;I have a task to use 2 authentication methods - local and SAML&amp;nbsp;on the single GP Portal and Gateway. First check local users and if username not found then check SAML users. As I know authentication sequence isn't supported for&amp;nbsp;SAML. Separating users by OS type isn't way for us because different users (SAML and local) can use the same OS type. Are there any ways to do this task on single firewall?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 16:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1220950#M6478</guid>
      <dc:creator>Dmytro-Ostapenko</dc:creator>
      <dc:date>2025-02-19T16:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Local and SAML  users authentication on the single GP Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221017#M6486</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1568421767"&gt;@Dmytro-Ostapenko&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only way I have seen this done is creating&lt;SPAN&gt;&amp;nbsp;a second portal/gw. Youd have one set w/ local auth and the other with SAML. What are the requirements behind the 2 separate auths? One for admins and another for regular users?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 22:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221017#M6486</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-02-19T22:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Local and SAML  users authentication on the single GP Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221155#M6497</link>
      <description>&lt;P&gt;Yes, one &lt;SPAN&gt;auth SAML Entra +2FA&amp;nbsp;&lt;/SPAN&gt;for admins and local auth for other users and services. Do we need second ISP link and public IP address in separate virtual router for&amp;nbsp;&lt;SPAN&gt;a second portal/gw or there is another way to deploy it?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 16:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221155#M6497</guid>
      <dc:creator>Dmytro-Ostapenko</dc:creator>
      <dc:date>2025-02-20T16:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Local and SAML  users authentication on the single GP Portal and Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221156#M6498</link>
      <description>&lt;P&gt;You don't need second ISP link if your current connection has more than 1 public IP.&lt;/P&gt;
&lt;P&gt;Assuming that you have /28 subnet and IP configured on WAN interface is 5.5.5.1/28 then add second IP 5.5.5.2/32 on the same interface and then you can use 5.5.5.2/32 for second GlobalProtect Portal/Gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 16:19:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/local-and-saml-users-authentication-on-the-single-gp-portal-and/m-p/1221156#M6498</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-02-20T16:19:03Z</dc:date>
    </item>
  </channel>
</rss>

