<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect MFA with RSA secureID with Radius in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/593571#M118136</link>
    <description>&lt;P&gt;Hello Abdullah,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you resolved your issue on 2FA with RSA Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2024 21:56:55 GMT</pubDate>
    <dc:creator>B.Alimov</dc:creator>
    <dc:date>2024-07-30T21:56:55Z</dc:date>
    <item>
      <title>Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260345#M73795</link>
      <description>&lt;P&gt;I have a customer who is trying to configure MFA in GP with RSA SecureID server with Radius server profile (Not the MFA profile that was introduced with 8.1).&lt;/P&gt;&lt;P&gt;The first factor should be user name and password and the second factor should be an OTP token.&lt;/P&gt;&lt;P&gt;Both username, passowrd and token should be validated by the RSA server.&lt;/P&gt;&lt;P&gt;I have done the configuration by following the below KB&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps.html#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now when i try to authenticate GP shows only the first step (Password), and it does not prompt for the OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i need to know if there is a configuration on GP to enable the OTP popup?&lt;/P&gt;&lt;P&gt;Also if am using an email/SMS token, the firewall should send a request first in order for the token to be generated, is there is a way to configure this method in PA?&lt;/P&gt;&lt;P&gt;also is there is a behavior change between 8.0 and 8.1 in the way GP handles MFA with Radius server profile?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 10:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260345#M73795</guid>
      <dc:creator>AbdallaAbdelkhaliq</dc:creator>
      <dc:date>2019-05-09T10:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260441#M73822</link>
      <description>&lt;P&gt;I think you are getting confused, the KB listed is 2 factor auth, not multi factor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so what is happening is you are logging into the portal with user and password, the portal then generates a cookie to auth you to the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you need multi factor without using MFA, the best you can do is have seperate auth servers on portal and gateways but unfortunately you are using same radius for both passcode and password...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does that make sense?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 17:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260441#M73822</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-05-09T17:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260621#M73875</link>
      <description>&lt;P&gt;Yes i tried using seperate auth profiles for portal and gateway and it works.&lt;/P&gt;&lt;P&gt;So you are saying that there is no way to use one authentication profile to do both token and password validation, and this is only available in the new MFA feature?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 09:21:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260621#M73875</guid>
      <dc:creator>AbdallaAbdelkhaliq</dc:creator>
      <dc:date>2019-05-12T09:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260622#M73876</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/84982"&gt;@AbdallaAbdelkhaliq&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you are asking for is possible. The problem here that GP does not ask for OTP isn't located on the firewall - it is a problem on your RSA server. When your RSA Radius server receives username and password (if the credentials are valid) it needs to reply with an Access-Challenge packet. This way GP would show the OTP prompt. Right now your RADIUS server sends back directly an access-accept packet so the firewall and GP see only a valid authentication without the need to ask for OTP.&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2019 09:55:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/260622#M73876</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-12T09:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292445#M77385</link>
      <description>&lt;P&gt;How do you make this response challenge happen from the RSA side-&amp;nbsp; i believe you are exactly correct on this.&amp;nbsp; &amp;nbsp;I just don't know how/where to do this on the RSA side.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 01:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292445#M77385</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-10-11T01:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292687#M77415</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you looked at the Authentication profiles and sequencing?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/authentication/configure-an-authentication-profile-and-sequence" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/authentication/configure-an-authentication-profile-and-sequence&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Might be worth a look. Also support is always around to help out if you need a resolution quicker.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 20:45:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292687#M77415</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-10-11T20:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292710#M77435</link>
      <description>&lt;P&gt;I've heard that Palos don't do auth sequences like you would like them to in this specific situation.....it will check for a successful authentication and when it takes, it stops.....it doesn't necessarily go through each one, every time....which is what we are looking for here i believe.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2019 13:33:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292710#M77435</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-10-12T13:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292711#M77436</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you are spot on here.....very correct.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2019 13:34:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/292711#M77436</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-10-12T13:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/295786#M77891</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunetely I have no idea on how to configure this on RSA RADIUS side - never used this product&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2019 21:59:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/295786#M77891</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-11-01T21:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/389247#M90610</link>
      <description>&lt;P&gt;In case anyone wants to read this, I have written a blog that helps with this subject here:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_3" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/blogs/dotw-mfa-and-2fa-for-gp-and-ngfw/ba-p/359778" target="_blank"&gt;DOTW: MFA and 2FA for GP and NGFW&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check it out.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 22:04:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/389247#M90610</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-04T22:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/389249#M90612</link>
      <description>&lt;P&gt;Just in case anyone wants to know, I have written a blog about this topic here:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_3" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/blogs/dotw-mfa-and-2fa-for-gp-and-ngfw/ba-p/359778" target="_blank"&gt;DOTW: MFA and 2FA for GP and NGFW&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be sure to check it out.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 22:12:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/389249#M90612</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-04T22:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect MFA with RSA secureID with Radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/593571#M118136</link>
      <description>&lt;P&gt;Hello Abdullah,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you resolved your issue on 2FA with RSA Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 21:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-mfa-with-rsa-secureid-with-radius/m-p/593571#M118136</guid>
      <dc:creator>B.Alimov</dc:creator>
      <dc:date>2024-07-30T21:56:55Z</dc:date>
    </item>
  </channel>
</rss>

