<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Native VPN client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223282#M64176</link>
    <description>&lt;P&gt;if GP is using OTP then it will fail on the gateway as it's probably using the same passcode twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if using OTP then setup cookie generation on the portal and cookie auth on the Gateway.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jul 2018 15:07:15 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-07-23T15:07:15Z</dc:date>
    <item>
      <title>Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223274#M64174</link>
      <description>&lt;P&gt;The native client on my windows machine does not seem to be authenticating against my radius/otp/ldap server and my globalprotect client is getting through the portal but failing on the gateway. Any ideas why or how to track it down?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 14:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223274#M64174</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T14:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223282#M64176</link>
      <description>&lt;P&gt;if GP is using OTP then it will fail on the gateway as it's probably using the same passcode twice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if using OTP then setup cookie generation on the portal and cookie auth on the Gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:07:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223282#M64176</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223284#M64177</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have have both the portal and the gateway set to use radius and OTP.&amp;nbsp; So where do I go to setup cookie generation?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why does the native client work and not ask for the OTP?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223284#M64177</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T15:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223285#M64178</link>
      <description>&lt;P&gt;the native client goes to the gateway directly, it does not use the portal so only has to auth once...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the settings are in network/portal/agent/configs.&amp;nbsp;&amp;nbsp; the settings are under authentication overide.&lt;/P&gt;&lt;P&gt;set the portal to generate cookie.&lt;/P&gt;&lt;P&gt;set portal to portal component only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and network/gateways/agent/client settings/configs..&amp;nbsp;&amp;nbsp; set this to accept cookie, use same cert for decrypt and set to low lifetime. 2 mins&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you need further help then i will post print screen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223285#M64178</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223286#M64179</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So tsounds like&amp;nbsp; the native client is not going to work with the OTP setup on the PA thats not good&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:25:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223286#M64179</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T15:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223287#M64180</link>
      <description>&lt;P&gt;Hmmmmm ... bit confused as i thought you said from the start that native was failing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but you then asked "Why does the native client work and not ask for the OTP?".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... er... erm&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the native should work OK. you can still have Radius auth on the gateway along with cookies. if the client has no cookie then it should challenge for OTP or whatever your Radius requires&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:29:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223287#M64180</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223295#M64181</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I can see where you might read that, no its not failing but it is not asking for a code to authenticate the native client, it is just allowing it with a username and password. So when I say not authenticating against the radius/OTP server I mean not prompting the user for the authcode/token, just letting them right in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So where is the best place to put the cookies on both the portal and gateway, just the portal or just the gateway. Our token has a limited life&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223295#M64181</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T15:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223296#M64182</link>
      <description>&lt;P&gt;OK so can we just confirm....&amp;nbsp;&amp;nbsp;&amp;nbsp; how many gateways do you have, is it just one for both GP and Native or one for each.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:39:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223296#M64182</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223298#M64183</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Correct one gateway for both the native and globalprotect client&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:43:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223298#M64183</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T15:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223299#M64184</link>
      <description>&lt;P&gt;OK and do you use multi factor auth on that gateway for GP users (LDAP and Radius)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or do GP users just use Radius.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223299#M64184</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223307#M64186</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I believe that the server was set up to do radius/OTP/LDAP and we have both the portal and the gateway set to that same server for multiauth&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223307#M64186</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T15:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223309#M64188</link>
      <description>&lt;P&gt;OK so i would assume that GP users can use ldap or OTP, and native client users can also use either ldap or OTP or have i missed something here..&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:58:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223309#M64188</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223310#M64189</link>
      <description>&lt;P&gt;what happens if native user tries OTP&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223310#M64189</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T15:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223311#M64190</link>
      <description>&lt;P&gt;Regarding your cookie auth for GP OTP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it depends on how much you trust the users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can set the cookie so that once generated it can be used all day to authenticate, probably dangerous if a device is lost or stolen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can also choose if it will auth both portal and gateway or just gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is how i use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;user connects with GP, GP prompts for username, PIN and OTP. if succesful then GP is issued a cookie, this is what is used to auth to the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only allow cookie for 1 min as user should reach the gateway a few seconds after authenticating to the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the user disconnects or is disconnected then they reconnect when they next need to and enter OTP again.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 16:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223311#M64190</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T16:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223312#M64191</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So do you set the auth profile for both the gateway and the portal to the radius/OTP/LDAP server and then set authentication overide to "Accept cookie for authentication override" on the gateway? Do you have to set "Generate cookie for authentication override on the portal" or no setting on the portal under authentication override?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I do know I want the prompt for the PIN/token on the portal and then passed to the gateway and a limited cookie time&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 16:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223312#M64191</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T16:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223315#M64192</link>
      <description>&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;So do you set the auth profile for both the gateway and the portal to the radius/OTP/LDAP server&lt;/STRONG&gt; &lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.&amp;nbsp; you don't really need it on the gateway for GP but you will need it for native.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;and then set authentication overide to "Accept cookie for authentication override" on the gateway?&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes. and set a time limit for how long you will accept the cookie. 10 mins is fine...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Do you have to set "Generate cookie for authentication override on the portal"&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&amp;nbsp;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Yes, but do not accept cookie for auth on portal. and put a tick in "portal" under the components section.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will force OTP everytime a user connects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 17:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223315#M64192</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T17:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223318#M64193</link>
      <description>&lt;P&gt;Gateway Settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gateway-cookie.png" style="width: 751px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16023iB9F89B4752EF48A4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gateway-cookie.png" alt="gateway-cookie.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 17:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223318#M64193</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T17:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223334#M64198</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if it is possible to do the 2 auth without using the cookies?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 18:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223334#M64198</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T18:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223338#M64199</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I swear there was a picture with this but I don't see it anymore&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 18:15:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223338#M64199</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-07-23T18:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Native VPN client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223341#M64201</link>
      <description>&lt;P&gt;Yes sorry the picture had some restricted info and couldnt edit it. So removed it. I will re post if needed but it was only portal info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im not sure what you mean by 2 auth... you can use OTP without cookie auth but user will have to wait for passcode to change for gateway auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats why the overide is offered on the palo.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 18:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/native-vpn-client/m-p/223341#M64201</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-23T18:27:26Z</dc:date>
    </item>
  </channel>
</rss>

