<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual Factor Authenticatin for Global Protect - possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/113083#M45185</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;have you checked out this article: &lt;A title=" GlobalProtect Dual Factor Authentication with Client Certificate for Windows" href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Dual-Factor-Authentication-with-Client-Certificate/ta-p/66167" target="_blank"&gt;GlobalProtect Dual Factor Authentication with Client Certificate for Windows&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have - but that's not really dual factor authentication in the context I'm using.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compromise a user account and steal a laptop/PC with the certificate already installed - and you're in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With an RSA os similar, you can steal the laptop, you can compromise the account, you can steal the token - but unless you're torturing the token owner for their PIN, you're not going to get in regardless of having the token.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Sep 2016 00:22:30 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2016-09-14T00:22:30Z</dc:date>
    <item>
      <title>Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112720#M45170</link>
      <description>&lt;P&gt;Folks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if it's possible to integrate dual-factor authentication (SecureID or similar) into Global protect authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our business is requiring more and more rigid access control for VPN access (among other things), and I need to look into getting some form of 2FA integrated into our VPN sign on in the short to medium term.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible? Any pointers to guides anywhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 04:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112720#M45170</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2016-09-13T04:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112774#M45171</link>
      <description>&lt;P&gt;have you checked out this article: &lt;A title=" GlobalProtect Dual Factor Authentication with Client Certificate for Windows" href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Dual-Factor-Authentication-with-Client-Certificate/ta-p/66167" target="_blank"&gt; GlobalProtect Dual Factor Authentication with Client Certificate for Windows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 07:40:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112774#M45171</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-09-13T07:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112862#M45173</link>
      <description>&lt;P&gt;We've been using Duo two factor along with requiring client certs on machines with a lot of success. This allows us to use two factor and ensure that we only have company approved equipment connect to the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the gateway set to use the Duo radius server (&lt;A href="https://duo.com/docs/authproxy_reference" target="_blank"&gt;https://duo.com/docs/authproxy_reference&lt;/A&gt;) for authentication, which then verifes against AD and sends&amp;nbsp;a push request to the users device to confirm authentication along with having a certificate profile setup to verify that a company issued AD cert is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the portal side we just have it verifying against AD directly with no certificate profile. That seems to be the best blend so users don't get requested to authenticate with two factor for config updates, just to actually log in.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 13:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112862#M45173</guid>
      <dc:creator>bgmncwj</dc:creator>
      <dc:date>2016-09-13T13:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112974#M45183</link>
      <description>&lt;P&gt;Is any doing any OTP dual factor setups. It would be cool to somehow use Google Authenticator as a second factor.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 17:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/112974#M45183</guid>
      <dc:creator>bbilut</dc:creator>
      <dc:date>2016-09-13T17:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/113083#M45185</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;have you checked out this article: &lt;A title=" GlobalProtect Dual Factor Authentication with Client Certificate for Windows" href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-Dual-Factor-Authentication-with-Client-Certificate/ta-p/66167" target="_blank"&gt;GlobalProtect Dual Factor Authentication with Client Certificate for Windows&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have - but that's not really dual factor authentication in the context I'm using.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Compromise a user account and steal a laptop/PC with the certificate already installed - and you're in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With an RSA os similar, you can steal the laptop, you can compromise the account, you can steal the token - but unless you're torturing the token owner for their PIN, you're not going to get in regardless of having the token.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 00:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/113083#M45185</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2016-09-14T00:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dual Factor Authenticatin for Global Protect - possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/113084#M45186</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12827"&gt;@bgmncwj&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;We've been using Duo two factor along with requiring client certs on machines with a lot of success. This allows us to use two factor and ensure that we only have company approved equipment connect to the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the gateway set to use the Duo radius server (&lt;A href="https://duo.com/docs/authproxy_reference" target="_blank"&gt;https://duo.com/docs/authproxy_reference&lt;/A&gt;) for authentication, which then verifes against AD and sends&amp;nbsp;a push request to the users device to confirm authentication along with having a certificate profile setup to verify that a company issued AD cert is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the portal side we just have it verifying against AD directly with no certificate profile. That seems to be the best blend so users don't get requested to authenticate with two factor for config updates, just to actually log in.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That looks like it might be a workable solution - and has specific guides for PAN setup - I'll give it a closer look - thanks for the pointer.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2016 00:25:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-factor-authenticatin-for-global-protect-possible/m-p/113084#M45186</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2016-09-14T00:25:59Z</dc:date>
    </item>
  </channel>
</rss>

