<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best method to permit SAML auth and Radius for Globalprotect at the same time? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/1222928#M123538</link>
    <description>&lt;P&gt;Yes, this seems to be very confusing in the documentation. As far as I have been able to determine and tested, there are 3 different methods of authentication which can not be interchanged in an authorization sequence: Certificates, SAML, and User/Password (via AD/LDAP/Radius/etc.).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is because the 3 methods occur at different points in the client connection. The certificate authentication happens during the initial SSL/TLS and webserver connection. The SAML authentication happens after connection is established and the server requests an authorization token before fulfilling the web request. The User/Password is after the client has connected, requested a page, is sent a login prompt, and has replied with a credential set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can't send a SAML token before you have established a certificate-verified web connection, and you can't submit user/pass responses before you have SAML-token-verified web request, you can't intermix these authentication methods. The AD/LDAP/Radius authentication sequences works as the client connects, is sent an authentication page, and returns a user/pass credential response. The PA can then test that single response against multiple authentication servers in the authorization sequence. Certificates and SAML don't use user/pass credentials.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 17:19:22 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2025-03-06T17:19:22Z</dc:date>
    <item>
      <title>Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586040#M116964</link>
      <description>&lt;P&gt;Greetings all, I hope you can help me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I currently have Globalprotect set up on a single firewall - both portal and gateway.&amp;nbsp; We're using Radius for authentication, it is working well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We want to transition to SAML.&amp;nbsp; For testing purposes, we'd like to have SAML configured for a specific test user (or group), while leaving the current authentication scheme in place.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Reordering "Client authentication" does not do it - if I put "SAML-GP" in the first position, SAML works, but no one else can authenticate.&amp;nbsp; I'm not sure I understand why client authentication order can be changed, but that's the behavior I'm getting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mannix_0-1715099765068.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59567iDD1446D53CF78692/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mannix_0-1715099765068.png" alt="mannix_0-1715099765068.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd RATHER not re-ip everything.&amp;nbsp; I'm thinking that a separate portal with different public IP is the answer; do I have to add a second gateway, too?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't THINK I do, if I simply specify the current gateway in the portal config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&amp;nbsp; Am I overcomplicating things?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Iain&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 16:42:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586040#M116964</guid>
      <dc:creator>mannix</dc:creator>
      <dc:date>2024-05-07T16:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586041#M116965</link>
      <description>&lt;P&gt;If you move SAML to the top then SAML takes precedence because your OS type is "any".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can't use both SAML and RADIUS on same portal/gateway at the same time for different groups of users.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 16:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586041#M116965</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-07T16:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586072#M116979</link>
      <description>&lt;P&gt;Thanks very much!&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I use a different portal for initial auth, then continue with my current gateway?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Iain&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 19:26:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586072#M116979</guid>
      <dc:creator>mannix</dc:creator>
      <dc:date>2024-05-07T19:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586167#M116993</link>
      <description>&lt;P&gt;Yes you can.&lt;/P&gt;
&lt;P&gt;Keep portal as is and set up new gateway.&lt;/P&gt;
&lt;P&gt;Using user or group membership point some users to new gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:04:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586167#M116993</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-08T13:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586173#M116994</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/89576"&gt;@mannix&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Greetings all, I hope you can help me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I currently have Globalprotect set up on a single firewall - both portal and gateway.&amp;nbsp; We're using Radius for authentication, it is working well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We want to transition to SAML.&amp;nbsp; For testing purposes, we'd like to have SAML configured for a specific test user (or group), while leaving the current authentication scheme in place.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Reordering "Client authentication" does not do it - if I put "SAML-GP" in the first position, SAML works, but no one else can authenticate.&amp;nbsp; I'm not sure I understand why client authentication order can be changed, but that's the behavior I'm getting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mannix_0-1715099765068.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59567iDD1446D53CF78692/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mannix_0-1715099765068.png" alt="mannix_0-1715099765068.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd RATHER not re-ip everything.&amp;nbsp; I'm thinking that a separate portal with different public IP is the answer; do I have to add a second gateway, too?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't THINK I do, if I simply specify the current gateway in the portal config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&amp;nbsp; Am I overcomplicating things?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Iain&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;We've recently switched to SAML auth for our GP, and we're told that if using SAML for auth that is the only auth mechanism that can be used.&amp;nbsp; So no matter how many mechanism you use in an auth profile if SAML is there only SAML will be used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not too sure how accurate that is, but that's what we were told from our SE.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 13:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586173#M116994</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-05-08T13:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586189#M116997</link>
      <description>&lt;P&gt;What about the inverse - adding a portal, and within that portal, configure my existing external gateway?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to create a situation where I can have test users authenticate with saml/Azure, without impacting our existing users.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My thought was to create a second portal, with a different public IP/natted to a loopback.&amp;nbsp; Check "&lt;SPAN&gt;Generate cookie for authentication override" in the authentication portion of the portal config.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That way, I can configure portal2 to use SAML, other users will be none the wiser.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What am I missing?&amp;nbsp; I _THINK_ this will work.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Iain&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:25:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/586189#M116997</guid>
      <dc:creator>mannix</dc:creator>
      <dc:date>2024-05-08T14:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/1222919#M123535</link>
      <description>&lt;P&gt;We trying to do the same thing in our environment. Support had told us that we could add SAML auth to our existing portal/gateway configuration and that users would connect via SAML if their user was in the auth source user list, if not they'd continue to connect via RADIUS. That turned out to be false!&lt;BR /&gt;&lt;BR /&gt;A second support tech informed us that you cannot do auth sequencing with SAML.&lt;BR /&gt;&lt;BR /&gt;So I now have an active case open with Palo support asking essentially the same question you're asking here. However, they are just linking me to KB articles about multiple gateway configurations, not multiple portal configurations. I cannot get a clear answer. Very frustrating.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 15:13:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/1222919#M123535</guid>
      <dc:creator>rfairfield</dc:creator>
      <dc:date>2025-03-06T15:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Best method to permit SAML auth and Radius for Globalprotect at the same time?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/1222928#M123538</link>
      <description>&lt;P&gt;Yes, this seems to be very confusing in the documentation. As far as I have been able to determine and tested, there are 3 different methods of authentication which can not be interchanged in an authorization sequence: Certificates, SAML, and User/Password (via AD/LDAP/Radius/etc.).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is because the 3 methods occur at different points in the client connection. The certificate authentication happens during the initial SSL/TLS and webserver connection. The SAML authentication happens after connection is established and the server requests an authorization token before fulfilling the web request. The User/Password is after the client has connected, requested a page, is sent a login prompt, and has replied with a credential set.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can't send a SAML token before you have established a certificate-verified web connection, and you can't submit user/pass responses before you have SAML-token-verified web request, you can't intermix these authentication methods. The AD/LDAP/Radius authentication sequences works as the client connects, is sent an authentication page, and returns a user/pass credential response. The PA can then test that single response against multiple authentication servers in the authorization sequence. Certificates and SAML don't use user/pass credentials.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 17:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/best-method-to-permit-saml-auth-and-radius-for-globalprotect-at/m-p/1222928#M123538</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2025-03-06T17:19:22Z</dc:date>
    </item>
  </channel>
</rss>

