<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect do not ask for OTP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227006#M65338</link>
    <description>&lt;P&gt;Hmn ... actually this is a setting on the RADIUS server where you define how the RADIUS server expects the password/otp, because the firewall only sends what it get from the user. The RADIUS server then answers with an ACCESS-ACCEPT, ACCESS-REJECT or ACCESS-CHALLENGE where the last one tells the firewall to show an additional inputprompt to the user where the OTP has to be entered.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2018 10:22:40 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-08-14T10:22:40Z</dc:date>
    <item>
      <title>Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/226888#M65313</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i had configured a radius server (freeradius) that work with google_authenticator and active directory. So far this works that way:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- login via Global Protect Client with username and AD Password+OTP (password and OTP in 1 promt)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to enter the OTP seperate and not together with the password. How can i achieve this??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal and the gateway had the same authentication profile (use the radius server for both, first google_authenticator (forward_pass to AD). Also i do not understand the "Componets that required Dynamic Passswords (Two Factor Authentication) option, if i enabled thsi for ext. Gateway or Portal the behavior did not change i had to enter password+otp in one promt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe i had to configure this on the radius server, but if i login via SSH using radius the client ask for the "verification Code" after the password is entered so i think it should be configured on the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 13:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/226888#M65313</guid>
      <dc:creator>Michael.Thyme</dc:creator>
      <dc:date>2018-08-13T13:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/226990#M65333</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12987"&gt;@Michael.Thyme&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you use the same Authentication Profile for GP and for admin access?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 00:06:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/226990#M65333</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-14T00:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227002#M65337</link>
      <description>&lt;P&gt;Hi vsys_remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;yes for the login into the web gui i use the same auth profile.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 07:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227002#M65337</guid>
      <dc:creator>Michael.Thyme</dc:creator>
      <dc:date>2018-08-14T07:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227006#M65338</link>
      <description>&lt;P&gt;Hmn ... actually this is a setting on the RADIUS server where you define how the RADIUS server expects the password/otp, because the firewall only sends what it get from the user. The RADIUS server then answers with an ACCESS-ACCEPT, ACCESS-REJECT or ACCESS-CHALLENGE where the last one tells the firewall to show an additional inputprompt to the user where the OTP has to be entered.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 10:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227006#M65338</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-14T10:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227019#M65342</link>
      <description>&lt;P&gt;ok thx.. i will&amp;nbsp;take a look at RADIUS site&amp;nbsp;and hopefuly change the behavior...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what do you think about the following workaround...:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Authtentication to Portal via LDAP auth profile (AD User + PW)&lt;/P&gt;&lt;P&gt;if success --&amp;gt;&lt;/P&gt;&lt;P&gt;2. Authentication to Gateway via RADIUS auth profile (Username (same format as AD Username) + OTP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i do not know if this is the good practise or insecure...&lt;/P&gt;&lt;P&gt;Is it possible to connect to the Gateway without connecting to the Portal first?&lt;/P&gt;&lt;P&gt;In this case that wouldnt be a workarround for us...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 12:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227019#M65342</guid>
      <dc:creator>Michael.Thyme</dc:creator>
      <dc:date>2018-08-14T12:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227053#M65348</link>
      <description>&lt;P&gt;Is your portal and gateway on the same device? If yes, then the chances that a client will connect directly to the portal are somewhere between low and not existent. Specially if you have the portal on another device than the gateway then the client will connect directly to the gateway if the portal is not available (if the client was already once connected and has a cached config)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;... but if your RADIUS is already doing what you need for the admin login, then there has to be a setting to force it this way ...&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227053#M65348</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-14T15:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227281#M65411</link>
      <description>&lt;P&gt;yes we host the Portal and the Gateway on the same device.. I was wondering that you wrote its "between low and not existent"&amp;nbsp; because my GP Clients always try to connect to the Portal and the Gateway.. So my plan was to use the password field as the input for the token only ..&amp;nbsp; so our active directory is called first while connecting to the portal (portal --&amp;gt; auth profile ldap)&lt;/P&gt;&lt;P&gt;if thsi is successful our clients try to connect to the Gateway where another authentication profile is set, wich only checks RADIUS (and the Radius do only check OTP via pam_google_authenticator), so the second Authentication process (connecting to the Gateway) is asking for username and password as usual but this time we only enter the OTP as the password.. but this only make sense for me if it is not possible to connect to portal or gateway seperatly.. you know what i mean?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i set the authentication profile to&amp;nbsp; 2FA for the admin login then it does the same as for GP it ask for username and password+OTP in one single promt..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the password(+OTP) is right the RADIUS is allways sending a "ACCESS-ACCEPT" instead of "ACCESS-CHALLENGE " i think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far as i understood, this behavior is made by the pam module (i.e. pam_google_authenticator) so i decide to install linOTP to my radius server, i think they use another pam module, maybe this is able to promt for OTP seperatly..&lt;/P&gt;&lt;P&gt;I will write if i had success..&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 13:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227281#M65411</guid>
      <dc:creator>Michael.Thyme</dc:creator>
      <dc:date>2018-08-16T13:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227330#M65426</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/12987"&gt;@Michael.Thyme&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I understood how you want to use the two authentications of the portal and gateway and I wrote of low chances because it might be possible that somehow the process for the portal could have a problem while the gateway still works properly. Ok, the propability is extremely low, but in theory it is possible.&lt;/P&gt;&lt;P&gt;I also read some things about the google_authenticator pam module and I came to the same conclusion as you: without some rewriting of the module it isn't possible that this authentication module will be access-challenge compatible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LinOTP is a very good idea I think. This way you will be able to configure the login flow in the LinOTP application (and in addition this software gives you way more possibilities about other configurations, user self registration, logging, ...)&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 18:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227330#M65426</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-16T18:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227336#M65429</link>
      <description>&lt;P&gt;yes i think the possibility that this can be happen is important..&lt;/P&gt;&lt;P&gt;we will see how linotp+freeradius+palo alto works for 2fa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your reply...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Aug 2018 18:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/227336#M65429</guid>
      <dc:creator>Michael.Thyme</dc:creator>
      <dc:date>2018-08-16T18:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect do not ask for OTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/416859#M93465</link>
      <description>&lt;P&gt;Hi Michael, did you success with this case, I also want to do the same authentication flow as your case (first username+password and then OTP)&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 15:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-do-not-ask-for-otp/m-p/416859#M93465</guid>
      <dc:creator>ThanhND</dc:creator>
      <dc:date>2021-07-02T15:14:48Z</dc:date>
    </item>
  </channel>
</rss>

