<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Two-Factor Authentication integration into PAN ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42140#M30973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To me it sounds odd that you need to install a "proxysoftware" in order to be able to speak to the authserver.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authserver should be able to speak standardized protocols such as radius for the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the client sends its credentials to the PA device. The PA device uses radius to ask the authserver (the OTP device) if the stuff the client sent is ok or not and then the authserver replies to this request which the PA will then either grant or deny access for the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look here for some info on the topic (integration between nordicedge and PA devices for use of OTP): &lt;A href="http://nordicedge.com/paloalto/" title="http://nordicedge.com/paloalto/"&gt; Strong authentication for Palo Alto Secure Access SSL VPN Solutions | Nordic Edge | The Provider of Secure Identity Solutions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Feb 2013 06:06:50 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-02-13T06:06:50Z</dc:date>
    <item>
      <title>VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42139#M30972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;recently I learned the Two-Factor Authentication solution from DUO Security. Basically it requires a PAN FW, an AD/Radius Proxy software provided by DUO Security and an Account/API Key.&lt;/P&gt;&lt;P&gt;The Proxy software is the interface between AD/Radius and DUO Servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since PAN already connects to an existing AD/Radius I am asking myself whether it would make sense to integrate the "proxy software" into PAN ? This would just require to enter the API Key in order to communicate with the DUO Servers on 443 and the extra proxy software is not required anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is valid for other Cloud OTP vendors as well, same technology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remember that a competitor in the firewall market did have or still has such a feature built in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you think ? Is this worth a feature request ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2013 11:20:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42139#M30972</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-02-12T11:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42140#M30973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To me it sounds odd that you need to install a "proxysoftware" in order to be able to speak to the authserver.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authserver should be able to speak standardized protocols such as radius for the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the client sends its credentials to the PA device. The PA device uses radius to ask the authserver (the OTP device) if the stuff the client sent is ok or not and then the authserver replies to this request which the PA will then either grant or deny access for the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look here for some info on the topic (integration between nordicedge and PA devices for use of OTP): &lt;A href="http://nordicedge.com/paloalto/" title="http://nordicedge.com/paloalto/"&gt; Strong authentication for Palo Alto Secure Access SSL VPN Solutions | Nordic Edge | The Provider of Secure Identity Solutions&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 06:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42140#M30973</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-13T06:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42141#M30974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well actually that was not my point, but even with NordicEdge (now McAfee) you need a local installation of a piece of software, they call it OTPServer same thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 07:15:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42141#M30974</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-02-13T07:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42142#M30975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but this server is the authserver itself, not a proxy that needs to be installed on the component asking for authorize incoming clients.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 06:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42142#M30975</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-14T06:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42143#M30976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same is true for the Duo Security Solution, don't get confused by product names.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2013 07:16:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42143#M30976</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-02-14T07:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42144#M30977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ahh, sorry about that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2013 08:07:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42144#M30977</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-02-15T08:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42145#M30978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Today I have configured and tested the Duo Security Two Factor Authentication with Global Protect and it works like a charm. All in all it took me about 45Mins. to get everything working (mostly because of waiting for the commit to be finished &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;Means installing and configuring&amp;nbsp; the Authentication Proxy Software provided by Duo on the Windows server, registering for a free Duo Account (up to 10 users free) and reconfiguring the PAN Firewall to use the authentication proxy as a Radius Server.&lt;/P&gt;&lt;P&gt;I really like the Duo Push functionality which makes it very easy and secure for an enduser to authenticate to the GP VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would love to see this integrated into the PAN Firewall out of the box as with this approach the authentication proxy would be obsolete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2013 15:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42145#M30978</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-02-19T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42146#M30979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Were you able to get the duo to work with the default integration (radius_server_iframe)?&amp;nbsp; I was told to drop back to using the radius_server_concat method, which is a bit rough around the edges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was that the global protect authentication dialog for the second factor would pop up with script in the prompt....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 20:28:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42146#M30979</guid>
      <dc:creator>JKoss</dc:creator>
      <dc:date>2013-05-29T20:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42147#M30980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to use the radius_server_concat method. The iframe method is needed for web based portal authentication like Citrix Access Gateway and such.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[main]&lt;/P&gt;&lt;P&gt;client=ad_client&lt;/P&gt;&lt;P&gt;server=radius_server_concat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ad_client]&lt;/P&gt;&lt;P&gt;host=IP_ADDRESS_OF_AD_SERVER&lt;/P&gt;&lt;P&gt;service_account_username=AD_USERNAME&lt;/P&gt;&lt;P&gt;service_account_password=AD_USERNAME_PASSWORD&lt;/P&gt;&lt;P&gt;search_dn=dc=COMPANY,dc=COM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[radius_server_concat]&lt;/P&gt;&lt;P&gt;api_host=API_HOST_ID.duosecurity.com&lt;/P&gt;&lt;P&gt;ikey=INTEGRATION_KEY&lt;/P&gt;&lt;P&gt;skey=SECURITY_KEY&lt;/P&gt;&lt;P&gt;failmode=safe&lt;/P&gt;&lt;P&gt;radius_ip_1=PAN_FW_IP_ADDRESS&lt;/P&gt;&lt;P&gt;radius_secret_1=RADIUS_PASSWORD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 21:01:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42147#M30980</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-05-29T21:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42148#M30981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick response-- that looks exactly like what I have configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just not sure about the need to specify the method (SMS,PUSH, etc.) on the password line. Change is hard when it comes to stuff like this and our users!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still, it is a very flexible system and seems like a good fit for us outside of that one issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 12:53:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42148#M30981</guid>
      <dc:creator>JKoss</dc:creator>
      <dc:date>2013-05-30T12:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42149#M30982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt; I'm just not sure about the need to specify the method (SMS,PUSH, etc.) on the password line. Change is hard when it comes to stuff like this and our users!&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's what I call a flexible system. We have a customer who decided to allow non privileged users to save password,push in the GP client and have them approve the authentication request on their smartphone. That's convenient.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 07:24:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42149#M30982</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2013-05-31T07:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Two-Factor Authentication integration into PAN ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42150#M30983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We tested solution SecurAccess from company SecurEnvoy. Is working well wilt PA for WIN/MAC GP. This is one solution where is possible use own GSM gateway for send SMS I found and reason I am writing.&lt;/P&gt;&lt;P&gt;Only I can't use native GP on Android phone for two auth currently.&lt;/P&gt;&lt;P&gt;Z. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 07:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-two-factor-authentication-integration-into-pan/m-p/42150#M30983</guid>
      <dc:creator>hsnetworks01</dc:creator>
      <dc:date>2013-05-31T07:47:41Z</dc:date>
    </item>
  </channel>
</rss>

