<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA 7.0, GP and RSA-ID double authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146808#M49267</link>
    <description>&lt;P&gt;A little bump, maybe still someone has some insight?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2017 08:18:21 GMT</pubDate>
    <dc:creator>nikoo</dc:creator>
    <dc:date>2017-03-09T08:18:21Z</dc:date>
    <item>
      <title>PA 7.0, GP and RSA-ID double authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146363#M49177</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a deployment with RSA-ID as OTP and GP as VPN client (3.1 or 3.0). PAN-OS version 7.0.14.&lt;/P&gt;&lt;P&gt;After the recent upgrade from 6.x to 7.x an issue showed up - when authenticating from GP - login information is asked twice.&lt;/P&gt;&lt;P&gt;This seems like a known issue:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.rsa.com/docs/DOC-46969" target="_blank"&gt;https://community.rsa.com/docs/DOC-46969&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've adjusted the PA settings according to this:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-with-RSA-OTP-behavior-change-from-PAN-OS-7-0-1-or/ta-p/65176" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-with-RSA-OTP-behavior-change-from-PAN-OS-7-0-1-or/ta-p/65176&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But that did not help, double authentication is still asked every time. GP client was reinstalled and local data cleared.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, after investigation of PA logs, it can be seen that when client connects, he's asked for the username and passcode (PIN+Code). After that the connection is accepted by RADIUS (RSA) and instantly there is a new request made by PA in a blink of an eye and that is rejected. Due to that a new login is required - after that connection succeeds, connection is accepted and VPN connection established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this really how it should work and there is no way around it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2017 12:02:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146363#M49177</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2017-03-07T12:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: PA 7.0, GP and RSA-ID double authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146808#M49267</link>
      <description>&lt;P&gt;A little bump, maybe still someone has some insight?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 08:18:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146808#M49267</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2017-03-09T08:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA 7.0, GP and RSA-ID double authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146831#M49272</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OTP is Ine Time Password .. but for GP, you need one auth onportal and one on gateway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Mean you need Two Time Password &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;or you just have to confogure on partial cookie generation and allow you rgatewy to use this cookie for authentication.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com.br/documentation/71/globalprotect/globalprotect-admin-guide/set-up-the-globalprotect-infrastructure/set-up-two-factor-authentication.html" target="_blank"&gt;https://www.paloaltonetworks.com.br/documentation/71/globalprotect/globalprotect-admin-guide/set-up-the-globalprotect-infrastructure/set-up-two-factor-authentication.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 10:29:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/146831#M49272</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2017-03-09T10:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA 7.0, GP and RSA-ID double authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/147787#M49439</link>
      <description>&lt;P&gt;Yea, it should be OTP, but turned out as TTP. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, fine, will upgrade to 7.1 when possible although there was a cookie to feed for the client in 7.0 as well, but that did not do the trick. We'll see if this will make it better.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 08:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-7-0-gp-and-rsa-id-double-authentication/m-p/147787#M49439</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2017-03-15T08:09:54Z</dc:date>
    </item>
  </channel>
</rss>

