<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure two-factor auth in GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22489#M16413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Hi Jeff,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;You are right, it won't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;You definitely need to have two ip-address for the gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;How about adding secondary ip on the interface and assigning second gateway profile to the secondary ip-address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:- &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Portal ip-&amp;nbsp;&amp;nbsp;&amp;nbsp; eth 1/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.54/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth 1/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.54/24 ( GW1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.110/32 (secondary ip)&amp;nbsp;&amp;nbsp; (GW2) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;One gateway :-&amp;nbsp; uses LDAP ,&amp;nbsp; tunnel.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Another gateway :- uses Radius, tunnel.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Should work. But will require gateway license.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Parth&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Oct 2012 23:18:03 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2012-10-02T23:18:03Z</dc:date>
    <item>
      <title>How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22479#M16403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone point me to a document for configuring two-factor authentication in GlobalProtect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 14:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22479#M16403</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T14:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22480#M16404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;You can do multi-factor by performing client cert auth in addition to authentication&lt;/SPAN&gt; t&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;o your LDAP/Radius/Kerberos server. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;I am not sure if you have gone through the following threads to see if it is useful:-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/10462#10462"&gt;https://live.paloaltonetworks.com/message/10462#10462&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/18731#18731"&gt;https://live.paloaltonetworks.com/message/18731#18731&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1934"&gt;https://live.paloaltonetworks.com/docs/DOC-1934&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Parth&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 15:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22480#M16404</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-02T15:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22481#M16405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp; However, I would like to use a token for the second pass.&amp;nbsp; Can I do that with GP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 15:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22481#M16405</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T15:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22482#M16406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Jeff,&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Yes, RADIUS (secure ID) can be used as a secondary means of authentication. Ensure that the username for the RADIUS authentication is configured for the GP gateway stage and&amp;nbsp; is the same as that which is used at the portal stage as you will not be prompted to add the username at the Gateway level&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;BR /&gt;You will however will allowed to enter the password and here is where you'd enter the RADIUS secure ID one time password&amp;nbsp; as the password&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Let me know if that helps.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Regards&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 15:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22482#M16406</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-02T15:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22483#M16407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me just confirm what you said. So, I can leave my GP Portal Auth Profile as AD but, I should change my Ext Gateway Auth Profile to be the Radius Proxy Server for my token system.&amp;nbsp; I'm not using SecureID, I'm using Duo Security.&amp;nbsp; The only thing is that the user credentials in the Radius Proxy Server needs to be the same as they are in AD.&amp;nbsp; Correct??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, when do I get prompted for the token password?&amp;nbsp; Will something pop up from the GP Client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Jeff &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 15:44:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22483#M16407</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T15:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22484#M16408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure two GP Gateways on the same interface?&amp;nbsp; I want to have one use AD for authentication for certain users and the other to use two-factor authentication for my advanced users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx, Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 22:10:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22484#M16408</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T22:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22485#M16409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be seeing the a dialogue box pop up at the gateway authentication. But as mentioned before, the username (from the AD )set for the portal authentication and the gateway should be the same as during the gateway authentication , we get a prompt to enter the one time password .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 22:17:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22485#M16409</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-02T22:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22486#M16410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I got that part working just fine.&amp;nbsp; I just was wondering if I can create two different External Gateway profiles that use the same interface.&amp;nbsp; So, I would have the GP Portal, Ext GW-1 and Ext GW-2 all bound to the same External Interface.&amp;nbsp; Can I do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx, Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 22:21:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22486#M16410</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T22:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22487#M16411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Never mind... I just tried it and it will not allow me to do what I want.&amp;nbsp; Unless, you know of another way to do it with one interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 22:34:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22487#M16411</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T22:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22488#M16412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not seen this implementation of having two gateway profiles associated to the a single gateway ip-address and am not 100% sure.&lt;/P&gt;&lt;P&gt;As per the tech note we can have One or more interfaces on one or more Palo Alto Networks firewalls that can be configured as gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 22:38:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22488#M16412</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-02T22:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22489#M16413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Hi Jeff,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;You are right, it won't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;You definitely need to have two ip-address for the gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;How about adding secondary ip on the interface and assigning second gateway profile to the secondary ip-address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:- &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Portal ip-&amp;nbsp;&amp;nbsp;&amp;nbsp; eth 1/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.54/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth 1/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.54/24 ( GW1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.30.6.110/32 (secondary ip)&amp;nbsp;&amp;nbsp; (GW2) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;One gateway :-&amp;nbsp; uses LDAP ,&amp;nbsp; tunnel.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Another gateway :- uses Radius, tunnel.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Should work. But will require gateway license.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Parth&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 23:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22489#M16413</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-02T23:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22490#M16414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the same idea in mind however, I can't put a secondary IP on the interface because I only have one Public IP address for that interface.&amp;nbsp; But, I see that would potentially work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for all of your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2012 23:52:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22490#M16414</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-02T23:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22491#M16415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ppatel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have for GP-portal ldap with attribute mail. In Radius RSA usernames are mail addres. But doen't work, when I captured radius packets comming from PA I saw the username mail addres is changed to domain.com\user.&lt;/P&gt;&lt;P&gt;So summary:&lt;/P&gt;&lt;P&gt;Portal:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;username: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:user1@domain.com"&gt;user1@domain.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;pwd: AD password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GW:&lt;/P&gt;&lt;P&gt;username send to RSA: domain.com\user1&lt;/P&gt;&lt;P&gt;pwd: OTP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But I get an error from RSA because he's waiting for &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:user1@domain.com"&gt;user1@domain.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Can this issue be solved? RSA users are only known by mail addres.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2012 19:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22491#M16415</guid>
      <dc:creator>kevin_thys</dc:creator>
      <dc:date>2012-10-26T19:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure two-factor auth in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22492#M16416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How about swapping the authentication profile for the Portal and the Gateway - RADIUS authentication on Portal and LDAP on the Gateway. RADIUS will push the &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:user1@domain.com"&gt;user1@domain.com&lt;/A&gt;&lt;SPAN&gt; to the gateway and then prompt. Not the typical configuration but will still do two factor authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 13:45:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-configure-two-factor-auth-in-globalprotect/m-p/22492#M16416</guid>
      <dc:creator>jcostello</dc:creator>
      <dc:date>2014-08-05T13:45:53Z</dc:date>
    </item>
  </channel>
</rss>

