<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN SSL Two factor authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120306#M45896</link>
    <description>&lt;P&gt;Palo's VPN native client is GlobalProtect, it really depends on what OTP vendor you are using to determine if it will function with it. They don't have a Web only client, you would need to use GlobalProtect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN functionality is free as long as you don't go past one Portal and one Gateway I believe that there is no user limit as long as your device can handle it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which firewall you should purchase is based on the number of clients; I would really read up on GlobalProtect on Palo Alto's main website to determine if this fits what you are looking to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Side Note: If the only thing you are doing is VPN on a Palo product and you aren't going to be using HIP checking, applicaiton ID, or any of the major Palo selling points I'm not sure why you would pick up a Palo product.&amp;nbsp;Setting it to the side of your network and using it as a VPN only device you lose everything that makes Palo products worth the price. In this case I would probably recommend an actual VPN Appliance or a cheap ASA 5505 if it was going to be used only for VPN.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2016 17:07:18 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2016-10-20T17:07:18Z</dc:date>
    <item>
      <title>VPN SSL Two factor authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120288#M45891</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i'm looking for a solution for VPN, that will support authentication in Active Directory and will support Two Factor authentication with OTP.&lt;/P&gt;&lt;P&gt;I read that GlobalProtect can provide me all features.&lt;/P&gt;&lt;P&gt;My questions:&lt;/P&gt;&lt;P&gt;is there any Palo Alto native VPN client or WEB client only ?&lt;/P&gt;&lt;P&gt;if there is native VPN client:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- does it support Windows 10 and OS X 10.11 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;- does it support OTP ?&lt;/P&gt;&lt;P&gt;If i'll buy some Palo Alto router should i pay for each VPN connection?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you recommend me some Palo Alto router? Main feature - VPN. Nothing else matters&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 15:11:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120288#M45891</guid>
      <dc:creator>Anahaym</dc:creator>
      <dc:date>2016-10-20T15:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL Two factor authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120306#M45896</link>
      <description>&lt;P&gt;Palo's VPN native client is GlobalProtect, it really depends on what OTP vendor you are using to determine if it will function with it. They don't have a Web only client, you would need to use GlobalProtect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN functionality is free as long as you don't go past one Portal and one Gateway I believe that there is no user limit as long as your device can handle it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which firewall you should purchase is based on the number of clients; I would really read up on GlobalProtect on Palo Alto's main website to determine if this fits what you are looking to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Side Note: If the only thing you are doing is VPN on a Palo product and you aren't going to be using HIP checking, applicaiton ID, or any of the major Palo selling points I'm not sure why you would pick up a Palo product.&amp;nbsp;Setting it to the side of your network and using it as a VPN only device you lose everything that makes Palo products worth the price. In this case I would probably recommend an actual VPN Appliance or a cheap ASA 5505 if it was going to be used only for VPN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 17:07:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120306#M45896</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-20T17:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL Two factor authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120388#M45906</link>
      <description>&lt;P&gt;Hi BPry,&lt;/P&gt;&lt;P&gt;thank you for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will use DUO OTP. It supports GlobalProtect.&lt;/P&gt;&lt;P&gt;Yes, we are looking only for a VPN solution for 30-40 users. How musch does cost a cheaper Solution from Palo Alto?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A had been asking Cisco... they offer from 4000 $.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 07:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120388#M45906</guid>
      <dc:creator>Anahaym</dc:creator>
      <dc:date>2016-10-21T07:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL Two factor authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120436#M45920</link>
      <description>&lt;P&gt;The Cisco solution that they are selling you is likely way over sec. You shouldn't need anything more than a 5508 with less than 50 users depending on your throughput requirements for those users. With just a VPN appliance I would actually be looking at something&amp;nbsp;that was stricktly an actual VPN appliance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 14:47:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-two-factor-authentication/m-p/120436#M45920</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-21T14:47:25Z</dc:date>
    </item>
  </channel>
</rss>

