<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588535#M3246</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I need to integrate my FortiAuthenticator, which is located at a remote site, with my PA firewall to add additional authentication factors for users connecting to GlobalProtect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't been able to find the documentation and procedures to accomplish this. I would appreciate it if someone with experience in this could provide the necessary requirements and configuration steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Sat, 01 Jun 2024 21:09:00 GMT</pubDate>
    <dc:creator>hamza_d</dc:creator>
    <dc:date>2024-06-01T21:09:00Z</dc:date>
    <item>
      <title>Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588535#M3246</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I need to integrate my FortiAuthenticator, which is located at a remote site, with my PA firewall to add additional authentication factors for users connecting to GlobalProtect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't been able to find the documentation and procedures to accomplish this. I would appreciate it if someone with experience in this could provide the necessary requirements and configuration steps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 21:09:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588535#M3246</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-06-01T21:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588580#M3250</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am guessing you are talking about the "native MFA" functionallity described here - &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi-factor-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi-factor-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There you can see that this can be only used with handful of third party IdPs like PingID, Okta, Duo - &lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However as any other firewall vendor you can enable MFA using any of the other standard authentication methods - RADIUS, TACACS, SAML.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find instructions how to configure any of these auth. protocols in the first link above. The next step is to enable the MFA, but this is all done on the FortiAuthenticator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 09:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588580#M3250</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-06-03T09:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588655#M3256</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex-shrink-0 flex flex-col relative items-end"&gt;
&lt;DIV&gt;
&lt;DIV class="pt-0.5 juice:pt-0"&gt;
&lt;DIV class="gizmo-bot-avatar flex h-6 w-6 items-center justify-center overflow-hidden rounded-full juice:h-8 juice:w-8"&gt;
&lt;DIV class="relative p-1 rounded-sm flex items-center justify-center bg-token-main-surface-primary text-token-text-primary h-8 w-8"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn"&gt;
&lt;DIV class="flex-col gap-1 md:gap-3"&gt;
&lt;DIV class="flex flex-grow flex-col max-w-full"&gt;
&lt;DIV class="min-h-[20px] text-message flex flex-col items-start whitespace-pre-wrap break-words [.text-message+&amp;amp;]:mt-5 juice:w-full juice:items-end overflow-x-auto gap-2" dir="auto" data-message-author-role="assistant" data-message-id="47ed1114-edf1-4402-9cd4-fc5ded088af6"&gt;
&lt;DIV class="flex w-full flex-col gap-1 juice:empty:hidden juice:first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert light"&gt;
&lt;P&gt;Could you clarify what you mean by "native MFA"? Based on your experience, which is recommended: using FortiAuthenticator as a RADIUS server or as an IdP server (SAML)?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 03 Jun 2024 23:30:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588655#M3256</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-06-03T23:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588877#M3273</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I am waiting for your response.&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 22:41:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588877#M3273</guid>
      <dc:creator>hamza_d</dc:creator>
      <dc:date>2024-06-05T22:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588947#M3274</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am guessing you are talking about the "native MFA" functionallity described here - &lt;A href="https://aeroshield.me/whatsapp-call-egypt/" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi-factor-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There you can see that this can be only used with handful of third party IdPs like PingID, Okta, Duo - &lt;A href="https://aeroshield.me/how-to-unblock-messenger-in-dubai/" target="_self"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However as any other firewall vendor you can enable MFA using any of the other standard authentication methods - RADIUS, TACACS, SAML.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find instructions how to configure any of these auth. protocols in the first link above. The next step is to enable the MFA, but this is all done on the FortiAuthenticator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am guessing you are talking about the "native MFA" functionallity described here - &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi-factor-authentication" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-multi-factor-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There you can see that this can be only used with handful of third party IdPs like PingID, Okta, Duo - &lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However as any other firewall vendor you can enable MFA using any of the other standard authentication methods - RADIUS, TACACS, SAML.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find instructions how to configure any of these auth. protocols in the first link above. The next step is to enable the MFA, but this is all done on the FortiAuthenticator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Native MFA means native multi factor authentication&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 13:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588947#M3274</guid>
      <dc:creator>OllyBe</dc:creator>
      <dc:date>2024-06-06T13:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating FortiAuthenticator with PA Firewall for Multi-Factor Authentication on GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588952#M3275</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/934742765"&gt;@hamza_d&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q: Could you clarify what you mean by "native MFA"?&lt;/P&gt;
&lt;P&gt;A: Please check the link I provided earlier. I have never had an use case to use this, but my understanding is that FW is communicating with some kind of API with one of those IdP services (Okta, Duo etc) instead of the using additional auth protocol&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q: Based on your experience, which is recommended: using FortiAuthenticator&lt;/P&gt;
&lt;P&gt;A: I would say this is heavilty depends on your requirements, environment and setup. Lately more people are prefering SAML mainly because it could provide great Single Sign-On experience for the end users. Also with RADIUS I am not sure you can have "push notification" for MFA, user will need to manually type the one-time-password. While with SAML you can have push notifcation, allowing the user just to click "approve" button&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 14:34:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/integrating-fortiauthenticator-with-pa-firewall-for-multi-factor/m-p/588952#M3275</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-06-06T14:34:39Z</dc:date>
    </item>
  </channel>
</rss>

