<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect requires token twice - Possible RSA inconvenience in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/175318#M54955</link>
    <description>&lt;P&gt;I think the first authentication dialogue is for portal, and the second time is for gateway. Since 7.x, &amp;nbsp;it uses the encrypted cookies to pass authentication information from portal to gateway. So that you will have only once for authentication.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2017 05:07:17 GMT</pubDate>
    <dc:creator>ericlinji</dc:creator>
    <dc:date>2017-09-07T05:07:17Z</dc:date>
    <item>
      <title>GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/166905#M53951</link>
      <description>&lt;P&gt;Hi Community. I have an issue on GP: it makes requests for token twice to get through VPN to my network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I discovered the RSAs feature "Next Token Code Mode", but believe PA (5050 - PAN-OS 7.1.10) has nothing to do when a NTC is requested, so I recommended my customer to open a case with RSA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead, my customer told me RSA answered this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.rsa.com/docs/DOC-46969" target="_blank"&gt;https://community.rsa.com/docs/DOC-46969&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Telling him that this is not a RSA issue, but a Palo Alto issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any info regarding this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 03:00:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/166905#M53951</guid>
      <dc:creator>gastong</dc:creator>
      <dc:date>2017-07-18T03:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/169939#M53952</link>
      <description>&lt;P&gt;Posted in the wrong group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should be posted in General Topics and not Community Feedback. &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Moving now.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 20:14:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/169939#M53952</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2017-08-03T20:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/170037#M53969</link>
      <description>&lt;P&gt;Have you configured "authentication overide" in the portal agent tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the portal will request authentication and then generate a cookie to authenticate you on the gateway. you need to "accept cookie authentication" in the gateway - agent - client settings - config for this to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you do not have this configured then the portal will request a passcode and then the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 09:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/170037#M53969</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-04T09:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/170054#M53972</link>
      <description>&lt;P&gt;&lt;A href="https://www.paloaltonetworks.it/documentation/80/globalprotect/globalprotect-admin-guide/authentication/enable-two-factor-authentication-using-one-time-passwords-otps.html" target="_blank"&gt;https://www.paloaltonetworks.it/documentation/80/globalprotect/globalprotect-admin-guide/authentication/enable-two-factor-authentication-using-one-time-passwords-otps.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2017 10:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/170054#M53972</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-08-04T10:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/175318#M54955</link>
      <description>&lt;P&gt;I think the first authentication dialogue is for portal, and the second time is for gateway. Since 7.x, &amp;nbsp;it uses the encrypted cookies to pass authentication information from portal to gateway. So that you will have only once for authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 05:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/175318#M54955</guid>
      <dc:creator>ericlinji</dc:creator>
      <dc:date>2017-09-07T05:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/243415#M69601</link>
      <description>&lt;P&gt;I run into the exact issue with PAN v8.0.12 with RSA GP client prompting RSA username and passcode twice (first will fail, and the second will succeed).&amp;nbsp; This issue only happens with GP clients (I've tried both v4.1.6 and v4.1.8).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I set the&lt;SPAN&gt;&amp;nbsp;"authentication overide" in the portal | agent | config | authentication, and choose "generate cookies for authentication overide" and "choose cerftificate to encrypt/decrypt cookies"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the Gateways | Agent | Client Settings | Configs | Authentication Override | choose "&lt;/SPAN&gt;&lt;SPAN&gt;"accept cookies for authentication overide" and "choose cerftificate to encrypt/decrypt cookies"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;GP client worked great with RSA after the configuration change.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks MickBall for your help!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: This issue happened to me only when using global protect client.&amp;nbsp; RSA works just fine with Clientless SSL VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 23:52:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/243415#M69601</guid>
      <dc:creator>hcao</dc:creator>
      <dc:date>2018-12-14T23:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/243480#M69613</link>
      <description>&lt;P&gt;When you are connecting to Global Protect you actually face two authentications: one authentication for the portal and one for the gateway. By default PAN firewall will try to use the same credentials provided for the portal again for the gateway. If you are using LDAP authentication for both (portal and gateway) the user will be asked for credetials only once, and he will get the impretion that only one authentication is happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Howeve if youare using OTP tokens the default behaviour wouldn't work. The reason for that is - once the user put his OTP when prompted by the &lt;STRONG&gt;portal &lt;/STRONG&gt;to authenticate, the firewall will cache the OTP and will try to sent it again to the Radius server (RSA server) when prompted to authenticate to the &lt;STRONG&gt;gateway&lt;/STRONG&gt;, howeve since this token has been already used the RSA will reply to the firewall with Access Reject message, which will force the firewall to prompt the user to enter credentials to authenticate to the &lt;STRONG&gt;gateway&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is why during user login in the RSA logs you probably will see:&lt;/P&gt;&lt;P&gt;- one successful login message (when user has authenticated with OTP to the portal)&lt;/P&gt;&lt;P&gt;- one failed login message (when firewall is using the same OTP to authenticate gainst the gateway)&lt;/P&gt;&lt;P&gt;- one successful login message (when user generate new OTP and authenticat to the gateway)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As other already suggested the solution will be to enable Authentication Override cookies. This will generate and install a auth. cookie on the user PC once he authenticate to the portal, when prompted to authenticate to the gateway the PC will use the cookie instead of prompting the user for credentials again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My suggestion:&lt;BR /&gt;- For the portal, enable only "generate cookie for authentication override". Do not enable "accept cookies", that way users will always be prompted to authenticate when connecting to the portal&lt;/P&gt;&lt;P&gt;- For the gateway, enable only "accept cookie" and set cookie lifetime to the minumim (one minute)&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 13:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/243480#M69613</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2018-12-17T13:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect requires token twice - Possible RSA inconvenience</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/1222773#M123513</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;I have attempted your suggestion in my lab environment, and it works well. Just to add to this also, although this suggestion is from 2018, it is still valid and worked well on PAN-OS version 11.1. I used Thales SafeNet OTP rather than RSA.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 12:29:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/m-p/1222773#M123513</guid>
      <dc:creator>AtulK</dc:creator>
      <dc:date>2025-03-05T12:29:27Z</dc:date>
    </item>
  </channel>
</rss>

