<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius &amp;amp; OTP Globalprotect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219337#M63328</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I checked with the server builder and apparrently twe do have radius,OTP and LDAP on the same server so we are good. I have most everything configured now so on to testing&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 19:53:13 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-06-26T19:53:13Z</dc:date>
    <item>
      <title>Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219120#M63290</link>
      <description>&lt;P&gt;So if I am configuring a a VPN to use radius &amp;amp; OTP (multi factor authentication) and LDAP. Do I add the radius authentication to both the portal and the gateway? and if so where and how does the LDAP authentication occur?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 15:20:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219120#M63290</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-25T15:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219164#M63293</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you stating you wish to do 3 authentication methods?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RADIUS -&amp;gt; OTP -&amp;gt;LDAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say that the OTP is your most secure and the LDAP and/or radius would be backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 18:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219164#M63293</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-25T18:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219166#M63294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;LOL, I guess that would be 3 factor indeed, as requested by my coworker and based on how it was set up on an ASA 5510 thant I am trying to replace. So do you think it is possible?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 19:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219166#M63294</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-25T19:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219172#M63296</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Actually I think that the Radius is serving out the OTP, I will have to check with the guy who is working on that portion of the VPN access&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219172#M63296</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-25T20:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219182#M63297</link>
      <description>&lt;P&gt;So OTP on the PAN is setup as radius. If its just OTP then LDAP that is 100% doable. In the past I just made the Portal Authentication the OTP and Gateway authentication LDAP. I havent tried the Multi-Factor Auth feature or the Authentication sequence.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 21:06:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219182#M63297</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-25T21:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219260#M63310</link>
      <description>&lt;P&gt;Correct the server that we created to do radius also has OTP on it and I have created a server profile for it. So what I need to know is do you set up radius for the portal and LDAP for the gateway or what combination does it have to be, which is what it sounds like you did? So does that mean they have to enter a username and password twice?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:38:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219260#M63310</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-26T12:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219263#M63311</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So when i was doing it, our OTP solution was an actual hand held time based token that a user had to enter the pin+code. So in this scenario, yes the user had to enter their username twice, once for each popup box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since then there have been some improvements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Integration-Articles/GlobalProtect-One-Time-Password-based-Two-Factor-Authentication/ta-p/155234" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Integration-Articles/GlobalProtect-One-Time-Password-based-Two-Factor-Authentication/ta-p/155234&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps#ided3529d7-1b3c-442e-b877-2bf2cd32d7d4" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps#ided3529d7-1b3c-442e-b877-2bf2cd32d7d4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your OTP is one of hte ones listed in the MultiFactor Authentication, the user experience should be different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219263#M63311</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-26T13:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219280#M63312</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes we do OTP on other things the same way with the a code generator.&amp;nbsp; I suspect our users will be prompted to long in twice as well and at this point we are limited to what 7.1.16 offers us since I have not had the time to upgrade to version 8 of the OS yet&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 14:51:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219280#M63312</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-26T14:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219286#M63315</link>
      <description>&lt;P&gt;I would do...&lt;/P&gt;&lt;P&gt;- LDAP only on the Portal&lt;/P&gt;&lt;P&gt;- RADIUS(OTP) on the Gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...Enabling 2-factor on the Portal may cause your users to have to enter in a OTP even when on your internal network.&amp;nbsp; Is your OTP solution capable of authenticating LDAP as well? (ex. LDAP+OTP over the RADIUS protocol).&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 15:47:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219286#M63315</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2018-06-26T15:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219288#M63317</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7542"&gt;@jambulo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;No my radius server for the OTP is not setup for LDAP and I don't believe it is capable of doing LDAP I am not really sure I would have to talk to the one who configured it.&lt;/P&gt;&lt;P&gt;We currently have this configuration set up using an ASA 5510 firewall, but it is going end of life so we are trying to replace it with a globalprotect VPN and that hits Radius/OTP followed by LDAP and we do want them to enter OTP even when on the internal network&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 15:53:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219288#M63317</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-26T15:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219298#M63319</link>
      <description>&lt;P&gt;It also looks, if i am reading it right, that you can configure it so it only makes you do the OTP login at the portal and passes the information encrypted , via cookie?, to the gateway&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 16:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219298#M63319</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-26T16:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219318#M63321</link>
      <description>&lt;P&gt;Yes we use cookie auth with OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it saves the user entering twice, plus, the user will have to wait the set time for a new passcode to be generated, depending on OTP system. We do not allow passcode re-use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also note that you are stuffed if the portal is unavailable for any reason and your GP client uses last known cached config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for what you require i would go Ldap for portal and OTP for gateway, this is assuming you have 3 factors for OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;something you are, have and know vs ldap, something you are and know.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 18:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219318#M63321</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-26T18:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219337#M63328</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I checked with the server builder and apparrently twe do have radius,OTP and LDAP on the same server so we are good. I have most everything configured now so on to testing&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 19:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219337#M63328</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-06-26T19:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Radius &amp; OTP Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219357#M63358</link>
      <description>&lt;P&gt;Good to hear. Also all traffic that the GP client passes after its initial contact with the Portal interface is encrypted. There are many ways to do this like Mich mentioned. Just depepnds on what you want to do and what the customer experience is.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 21:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-amp-otp-globalprotect-vpn/m-p/219357#M63358</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-26T21:18:11Z</dc:date>
    </item>
  </channel>
</rss>

