<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect MFA with Google Authenticator in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-with-google-authenticator/m-p/549467#M112119</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287184"&gt;@SandipKumbhar&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS does not support Google MFA natively -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table#id17CBB0W095Z" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table#id17CBB0W095Z&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One solution that you can use is a RADIUS server that supports both LDAP and Google TOTP, e.g. &lt;A href="https://sysopstechnix.com/enable-2fa-on-freeradius-with-openldap-users/" target="_blank"&gt;https://sysopstechnix.com/enable-2fa-on-freeradius-with-openldap-users/&lt;/A&gt;.&amp;nbsp; I just Googled that one.&amp;nbsp; I have not used it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the NGFW, all you do is configure the RADIUS server for GlobalProtect.&amp;nbsp; Check out the diagram in the 2nd URL.&amp;nbsp; If you do not want users to get prompted twice for MFA (portal and gateway), you can (1) enable authentication cookies or (2) use RADIUS for the portal and LDAP for your gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2023 01:49:16 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2023-07-17T01:49:16Z</dc:date>
    <item>
      <title>Global Protect MFA with Google Authenticator</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-with-google-authenticator/m-p/549370#M112094</link>
      <description>&lt;P&gt;Dear Team,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me understand can we configure TOTP Google Authenticator(Free) for Global Project VPN users&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we have configured Global Protect VPN with AD authentication and want to configure the above solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in Advance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sandip Kumbhar&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 11:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-with-google-authenticator/m-p/549370#M112094</guid>
      <dc:creator>SandipKumbhar</dc:creator>
      <dc:date>2023-07-14T11:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA with Google Authenticator</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-with-google-authenticator/m-p/549467#M112119</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/287184"&gt;@SandipKumbhar&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PAN-OS does not support Google MFA natively -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table#id17CBB0W095Z" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table#id17CBB0W095Z&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One solution that you can use is a RADIUS server that supports both LDAP and Google TOTP, e.g. &lt;A href="https://sysopstechnix.com/enable-2fa-on-freeradius-with-openldap-users/" target="_blank"&gt;https://sysopstechnix.com/enable-2fa-on-freeradius-with-openldap-users/&lt;/A&gt;.&amp;nbsp; I just Googled that one.&amp;nbsp; I have not used it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the NGFW, all you do is configure the RADIUS server for GlobalProtect.&amp;nbsp; Check out the diagram in the 2nd URL.&amp;nbsp; If you do not want users to get prompted twice for MFA (portal and gateway), you can (1) enable authentication cookies or (2) use RADIUS for the portal and LDAP for your gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 01:49:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-with-google-authenticator/m-p/549467#M112119</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-07-17T01:49:16Z</dc:date>
    </item>
  </channel>
</rss>

