<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protec in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218160#M63072</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt;&lt;/P&gt;&lt;P&gt;This sounds more like an issue on your RSA RADIUS server as it depends on the configuration on that server how the authentication flow should look like.&lt;/P&gt;&lt;P&gt;From my own experiences I know two types of authentication flows&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;User enters username and in the password field his OTP and also the password. This way the RADIUS server is able to check all login factors at once and returns access-accept or access-reject&lt;/LI&gt;&lt;LI&gt;User enters username and password and klicks login. Then the RADIUS server checks these credentials and if correct it sends a RADIUS access-challenge packet to the firewall which then displays a new inputfield for the OTP.&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Sun, 17 Jun 2018 17:33:58 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-06-17T17:33:58Z</dc:date>
    <item>
      <title>How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protect ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218121#M63054</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protect ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal = Radius (RSA) passes -&amp;gt; LDAP check&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jun 2018 04:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218121#M63054</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-06-16T04:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218160#M63072</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56277"&gt;@junior_r&lt;/a&gt;&lt;/P&gt;&lt;P&gt;This sounds more like an issue on your RSA RADIUS server as it depends on the configuration on that server how the authentication flow should look like.&lt;/P&gt;&lt;P&gt;From my own experiences I know two types of authentication flows&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;User enters username and in the password field his OTP and also the password. This way the RADIUS server is able to check all login factors at once and returns access-accept or access-reject&lt;/LI&gt;&lt;LI&gt;User enters username and password and klicks login. Then the RADIUS server checks these credentials and if correct it sends a RADIUS access-challenge packet to the firewall which then displays a new inputfield for the OTP.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Sun, 17 Jun 2018 17:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218160#M63072</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-17T17:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218228#M63090</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The way I acheived this in the past was to use different authentication methods for Portal and Gateway. I would use the Portal Radius for OTP and then LDAP for the Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:23:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218228#M63090</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-18T13:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: How can I get user to type username, password and OTP when using RSA Radius 8,1 on Global Protec</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218265#M63099</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;For something like this there is also the way to configure authentication cookies. So you could configure the same RADIUS profile on the gateway without degrading the security with an authentication profile without OTP on the gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 17:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-get-user-to-type-username-password-and-otp-when-using/m-p/218265#M63099</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T17:56:01Z</dc:date>
    </item>
  </channel>
</rss>

