<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184338#M56546</link>
    <description>&lt;P&gt;So.. to confirm... if you just change the portal config to on demand... does it work ok..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also... are you sure you have sso turned off in portal conf and save password to no.&lt;/P&gt;</description>
    <pubDate>Sun, 29 Oct 2017 19:22:13 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-10-29T19:22:13Z</dc:date>
    <item>
      <title>Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184324#M56541</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone gotten GP user-logon (ALWAYS on) and OTP working toghther?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 10:32:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184324#M56541</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-29T10:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184332#M56542</link>
      <description>&lt;P&gt;As GP tries to connect, do you get a username and password prompt?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 12:04:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184332#M56542</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-29T12:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184335#M56544</link>
      <description>&lt;P&gt;Yes but problem is when I logon to Windows it trys to take those creds and send it to Portal, which causes auth errors in LOG. After this I can get in. I want to prevent the first auth error when logging into the PC&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 15:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184335#M56544</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-29T15:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184338#M56546</link>
      <description>&lt;P&gt;So.. to confirm... if you just change the portal config to on demand... does it work ok..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also... are you sure you have sso turned off in portal conf and save password to no.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 19:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184338#M56546</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-29T19:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184347#M56548</link>
      <description>&lt;P&gt;Hi Junior_r,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you using the same auth profile for both portal and gateway? I suspect what is happening is that you are trying to do SSO/Authentication twice with the same OTP, so authenticating once against the portal and again against the gateway with the same OTP. Most OTP operators make it so that you can't use the same OTP twice, so your authentication is failing on the second go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way to get around this is to use two different authentication profiles, one for the portal and one for the gateway. The portal authentication will be set as your standard login with username and password and your gateway config will have the auth profile set to use the OTP login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This way you will auth once to the portal with username/password, then you'll need to authenticate again against the gateway and thus be prompted for your OTP code.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can combine this with cookie authentication for the portal so&amp;nbsp;after a first successful login to the portal this authentication gets cached and only a single authetncation using the OTP is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 20:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184347#M56548</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-10-29T20:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184348#M56549</link>
      <description>&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply. Can I use SSO for portal and use OTP for Gateway when using&amp;nbsp;user-logon? Would SSO try to send creds to to gateway also or would SSO send creds to portal then promote user for OTP for gateway? What if I only enable OTP,&amp;nbsp;user-logon and disable SSO. After user logs on would it promote them for their OTP without them opening GP client?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 21:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184348#M56549</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-29T21:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184382#M56554</link>
      <description>&lt;P&gt;Hi junior_r,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SSO will try to authenticate against both portal and gateway. So you'll either need to keep SSO on and live with the error message of the 1st auth against the gateway or disable it and enter the username and password on the login screen and GP after login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Single-Sign-on-SSO-for-GlobalProtect/ta-p/112186" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Tips-amp-Tricks-Single-Sign-on-SSO-for-GlobalProtect/ta-p/112186&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally I think the first option is the best as it is more seamless to users, they will log in on the login window with their username and password and then be prompted for the OTP by GP, they won't see that it has failed the 1st gateway authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 09:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184382#M56554</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-10-30T09:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone gotten GP user-logon (ALWAYS on) and OTP working together?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184461#M56571</link>
      <description>&lt;P&gt;Thanks Ben this works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 13:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/has-anyone-gotten-gp-user-logon-always-on-and-otp-working/m-p/184461#M56571</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-30T13:51:24Z</dc:date>
    </item>
  </channel>
</rss>

