<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec X-Auth with RSA On-Demand Tokens in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23077#M16840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have the same issue now.I don't know what is different when x-auth is selected.We are using Radius Auth. for OTP.&lt;/P&gt;&lt;P&gt;when trying from phone-xauth no auht. traffic is going to Radius server.&lt;/P&gt;&lt;P&gt;but with a client Pc it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jun 2013 08:36:47 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-06-20T08:36:47Z</dc:date>
    <item>
      <title>IPsec X-Auth with RSA On-Demand Tokens</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23075#M16838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I have PAN working with RSA On-Demand tokencodes (these are SMS-based tokens) when using GlobalProtect and the management UI but cannot get it to work with IPsec X-Auth. RSA On-Demand tokens work like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) User enters their username and PIN to log in&lt;/P&gt;&lt;P&gt;2) Firewall sends RADIUS Authentication message to RSA server which, if the PIN is valid, sends a text message to the user with their tokencode.&lt;/P&gt;&lt;P&gt;3) The RSA server then sends a RADIUS Challenge message to the firewall, asking for the tokencode.&lt;/P&gt;&lt;P&gt;4) The user receives the text message and enters their tokencode into the new login challenge field.&lt;/P&gt;&lt;P&gt;5) The firewall sends the tokencode to the RSA server for validation.&lt;/P&gt;&lt;P&gt;6) If the tokencode is legitimate, the RSA server sends a successful RADIUS message to the firewall, which then logs the user in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like I mentioned, this all works great with GlobalProtect and the management UI but fails when using IPsec X-Auth at steps 3-4. The user receives the text message with their tokencode but the firewall returns a failed authentication message to the user rather than challenging them for the tokencode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else seen this or been able to get it working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 17:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23075#M16838</guid>
      <dc:creator>codyhatch</dc:creator>
      <dc:date>2012-12-20T17:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec X-Auth with RSA On-Demand Tokens</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23076#M16839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe this would be a bug/feature request IMO &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2013 00:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23076#M16839</guid>
      <dc:creator>kkeeton</dc:creator>
      <dc:date>2013-01-18T00:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec X-Auth with RSA On-Demand Tokens</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23077#M16840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have the same issue now.I don't know what is different when x-auth is selected.We are using Radius Auth. for OTP.&lt;/P&gt;&lt;P&gt;when trying from phone-xauth no auht. traffic is going to Radius server.&lt;/P&gt;&lt;P&gt;but with a client Pc it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-x-auth-with-rsa-on-demand-tokens/m-p/23077#M16840</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-20T08:36:47Z</dc:date>
    </item>
  </channel>
</rss>

