<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 factor authentication issue on Palo Alto Global Protect client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/176773#M55231</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We as well use LDAP at auth portal, SSO at portal config&amp;nbsp;level and OTP at Gateway level it works fine...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However for better end user usablity we had to enable authentication cookie override at Gateway level as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for this to work fine we&amp;nbsp;had to&amp;nbsp;deactivate SSO&amp;nbsp;(as SSO&amp;nbsp;can create username invalid issues...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything looks stable so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2017 09:27:57 GMT</pubDate>
    <dc:creator>plevesque</dc:creator>
    <dc:date>2017-09-27T09:27:57Z</dc:date>
    <item>
      <title>2 factor authentication issue on Palo Alto Global Protect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/151162#M50094</link>
      <description>&lt;P&gt;we need support from Palo Alto to understand the following issue:&lt;BR /&gt;&lt;BR /&gt;A portal and gateway profile has been created for ¿internal¿&amp;nbsp; users and ¿external¿ business partner users. All users need to authenticate using OTP (One time passcode). By default users must first authenticate against Portal and second to Gateway. Unfortunately this means that users have to fill in twice an OTP. The authentication flow is as follows:&lt;BR /&gt;-They are asked for the OTP first time for the portal&lt;BR /&gt;-PA tries to use the same OTP to authenticate on the Gateway&lt;BR /&gt;-the authentication provide does not accept the same OTP twice so replies with a Auth reject&lt;BR /&gt;-PA prompts the user for the OTP again (for the user looks like a failed authentication)&lt;BR /&gt;This causes confusion as most users will try to authenticate again with same OTP and authentication fails.&lt;BR /&gt;&lt;BR /&gt;PAN has an option call authentication override for Portal and Gateway. When enabling authentication override on Portal users have to authenticate twice first time but at the same time a cookie is set on client valid for one year. Next time users connect to GP they only have to authenticate once, against gateway, as client cookie is presented to PA firewall being accepted.&lt;BR /&gt;&lt;BR /&gt;However this solution still asks for double auth first time and then every year or when the cookie is lost.&lt;BR /&gt;&lt;BR /&gt;Is there a better option to avoid asking for 2 OTPs when loggin in to Global Protect?&lt;BR /&gt;Please raise this issue with Palo Alto, as we are receiving complaints from end users quite often.&lt;BR /&gt;&lt;BR /&gt;Version 7.0.9 is running on PA-500.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 02:11:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/151162#M50094</guid>
      <dc:creator>mss-ops</dc:creator>
      <dc:date>2017-04-05T02:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: 2 factor authentication issue on Palo Alto Global Protect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/151189#M50099</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/843"&gt;@mss-ops&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You probably need PAN-OS 7.1 which has enhanced 2 factor authentication&amp;nbsp;features :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/globalprotect-features/enhanced-two-factor-authentication.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/newfeaturesguide/globalprotect-features/enhanced-two-factor-authentication.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 08:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/151189#M50099</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-04-05T08:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: 2 factor authentication issue on Palo Alto Global Protect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/171731#M54266</link>
      <description>&lt;P&gt;Was having the same issue and you describing it out helped me fix it by using LDAP auth for the Portal and Radius using OTP for the Gateway. Eliminated the double prompt for OTP and auth successfully the first attempt.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 20:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/171731#M54266</guid>
      <dc:creator>jake.britt87</dc:creator>
      <dc:date>2017-08-15T20:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: 2 factor authentication issue on Palo Alto Global Protect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/176773#M55231</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We as well use LDAP at auth portal, SSO at portal config&amp;nbsp;level and OTP at Gateway level it works fine...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However for better end user usablity we had to enable authentication cookie override at Gateway level as well&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for this to work fine we&amp;nbsp;had to&amp;nbsp;deactivate SSO&amp;nbsp;(as SSO&amp;nbsp;can create username invalid issues...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything looks stable so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 09:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/176773#M55231</guid>
      <dc:creator>plevesque</dc:creator>
      <dc:date>2017-09-27T09:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2 factor authentication issue on Palo Alto Global Protect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/178156#M55472</link>
      <description>&lt;P&gt;Yeah, this has been an issue since 7.1 for us as well. We migrated to certificate authentication for the portal, but certificates might not work for everyone as you have to push them to devices first&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 17:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-issue-on-palo-alto-global-protect-client/m-p/178156#M55472</guid>
      <dc:creator>PavloJCP</dc:creator>
      <dc:date>2017-09-21T17:51:35Z</dc:date>
    </item>
  </channel>
</rss>

