<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 Factor Auth Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154337#M50865</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having issue with GlobalProtect VPN client when using&amp;nbsp;2 Factor Authorisation to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of being presented with a second login prompt to enter the code from the keyfob, Palo Alto is rejecting logins unless the keyfob code is appended to the user’s password on the initial login prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we change this to the desired behaviour of the second login prompt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 04:10:44 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2017-04-27T04:10:44Z</dc:date>
    <item>
      <title>2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154337#M50865</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having issue with GlobalProtect VPN client when using&amp;nbsp;2 Factor Authorisation to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of being presented with a second login prompt to enter the code from the keyfob, Palo Alto is rejecting logins unless the keyfob code is appended to the user’s password on the initial login prompt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we change this to the desired behaviour of the second login prompt?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 04:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154337#M50865</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-04-27T04:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154370#M50871</link>
      <description>&lt;P&gt;this sounds like normal behavior to me based on my experience with RSA SecurID (not with GP, though).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MFA doesn't necessarily mean multiple prompts, it just means something you know (PIN) + something you have (one time password).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the only time I've seen SecurID act like I believe you're expecting it to is with on demand authentication in which one first enters their PIN, then receives the one time password via email or text, so there has to be a second prompt for that.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 09:35:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154370#M50871</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-27T09:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154397#M50880</link>
      <description>&lt;P&gt;That's normal depending on your 2-factor setup.&lt;/P&gt;&lt;P&gt;The GP client has no idea that it's supposed to feed the second prompt because it simply recieves the authentication failed message, and in reality it has failed becauses it doesn't match what your AD/Radius server is expecting.&amp;nbsp;This in turn causes the authentication to fail/timeout. The workaround for a setup like this is to either&lt;/P&gt;&lt;P&gt;A)&amp;nbsp;Depending on the multifactor solution (like RSA) you can tie the password it feeds through to a certain account. So if I&amp;nbsp;have my token assigned to my 'administrator' account &amp;nbsp;my 'normal' unpriveleged account incounters an additional password dialog as the password stored by RSA no-longer matches the password for my 'normal' account. You would have to switch the token to being tied to the 'normal' account and then the additional password dialog would happen when I utilize my 'administrator' account.&lt;/P&gt;&lt;P&gt;B) Exactly what you currently have users doing.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 15:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154397#M50880</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-27T15:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154596#M50915</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What version of the GP client are you using. I know I had issues with certain versions where they would not give me the second prompt. I have GP setup to have different authentications for portal and gateway, this way we get the first prompt for username/passowrd and then a second one for the other auth method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Agent&amp;nbsp;&lt;SPAN&gt;2.3.3&lt;/SPAN&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;is currently stable for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2017 20:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154596#M50915</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-04-28T20:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154654#M50922</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i&lt;SPAN&gt;s the “on demand” option you mentioned usable with a keyfob or must the one-time code be emailed/SMSed?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Apr 2017 23:04:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154654#M50922</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-04-30T23:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154684#M50934</link>
      <description>&lt;P&gt;on demand is via sms/email. out of hardware, software and oda, it's the chepeast and most versatile option (I've managed all 3).&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 14:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/154684#M50934</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-05-01T14:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155220#M51058</link>
      <description>&lt;P&gt;Thanks to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58582"&gt;@bradk14&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;for the responses. Very helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One last question: Does PA GP VPN support&amp;nbsp;client certificate combined with RADIUS authentication with the client running in On Demand mode?&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 04:39:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155220#M51058</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-05-05T04:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155250#M51072</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So you want to check for a client certificate and ask for username and password; or is it that you simply want it to fall back to RADIUS authentication if the device doesn't have a client cert?&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 13:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155250#M51072</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-05-05T13:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Factor Auth Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155456#M51123</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We want to check for a client certificate and ask for a username/password (to be authenticated bvy RADIUS) using on-demand mode.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 22:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-auth-issue/m-p/155456#M51123</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-05-07T22:42:29Z</dc:date>
    </item>
  </channel>
</rss>

