<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2FA on both portal and gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230196#M66179</link>
    <description>&lt;P&gt;ooer... this could get confusing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for native clients, just the gateway but if you have GP clients then you will also need it on the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having it on both without cookie....&amp;nbsp;&amp;nbsp;&amp;nbsp; well it's an OTP so it cannot be used again for the gateway, thats why the authentication overide (cookie stuff)is there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 16:57:36 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-09-10T16:57:36Z</dc:date>
    <item>
      <title>2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/229975#M66121</link>
      <description>&lt;P&gt;If you have two factor auth on the portal and the gateway without using the cookie or passing the auth from the portal to the gateway will it ask you to authenticate twice?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 13:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/229975#M66121</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-07T13:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230007#M66129</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 16:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230007#M66129</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-07T16:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230019#M66137</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Makes sense that it would, but I can pass the authentication if I choose the cookie option can't I? I be that is what the native clients are not getting the routing information from the gateway cause they are only asked to authenticate once&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 16:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230019#M66137</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-07T16:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230047#M66143</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;, hope you are well...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I dont think, in fact im pretty sure that native clients do not use the portal, they connect directly to the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so either i have got that wrong or you are having some other issues with routing info...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 19:17:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230047#M66143</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-07T19:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230050#M66145</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;hope you are doing well too....&lt;/P&gt;&lt;P&gt;Well I had never thought of that, interesting. Do you know the technical reason why? Seems like if it went to the gateway it should get the route information&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 19:26:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230050#M66145</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-07T19:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230052#M66147</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Not really a technical answer, but IPSec deployments are never implemented the same across devices.&amp;nbsp;The firewall will only send route infromation in a certain manner, whether the end-device has been programmed to accept the route as given is a different story. Most vendors won't take the time to implement every single possible method and don't generally keep up with the changes made throughout all the different implementations. This is why VPN clients are offered; they can ensure that they are both passing/expecting the proper information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm fairly positive that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;is correct in the fact that native clients do not utilize the portal in the connection process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 19:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230052#M66147</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-07T19:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230054#M66149</link>
      <description>&lt;P&gt;Spot on&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 07:36:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230054#M66149</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-08T07:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230147#M66174</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So I have both radisu and OTP enabled on the gateway and the portal do I need it on both&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 14:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230147#M66174</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-10T14:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230196#M66179</link>
      <description>&lt;P&gt;ooer... this could get confusing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for native clients, just the gateway but if you have GP clients then you will also need it on the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;having it on both without cookie....&amp;nbsp;&amp;nbsp;&amp;nbsp; well it's an OTP so it cannot be used again for the gateway, thats why the authentication overide (cookie stuff)is there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 16:57:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230196#M66179</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-10T16:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230259#M66192</link>
      <description>&lt;P&gt;So about these cookies .....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cookie Sir.jpg" style="width: 235px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16503i60CCF115AD4D9CEE/image-dimensions/235x318/is-moderation-mode/true?v=v2" width="235" height="318" role="button" title="Cookie Sir.jpg" alt="Cookie Sir.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In all seriousness in your situation&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp;I would really recommend that you keep OTP on both and then just enable authentication override so that users don't have to enter the OTP twice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 00:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230259#M66192</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-11T00:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230328#M66209</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;coooookkkkiiiieee. Love the cookie monster picture. So how will authentication override affect those user using the native client?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 12:52:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230328#M66209</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-11T12:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230330#M66211</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So application override is set in the portal and then the information is passed onto the gateway? Course I am only going to do based on the affect it has on the native client&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 12:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230330#M66211</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-11T12:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230334#M66214</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So the authentication override doesn't come into play with the Native clients, because they are only connecting to the gateway. Where the authentication override will come into play is when the GP agents login they will then only need to enter the OTP once when you get cookie Auth properly setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:21:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230334#M66214</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-11T13:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230336#M66216</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So do you select&amp;nbsp;&amp;nbsp;generate cookie for the overide&amp;nbsp;on the portal and accept cookie on the gateway? It make even less sense that the native client doesn't get the routes from the gateway since is connecte directly to it&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:27:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230336#M66216</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-11T13:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230344#M66218</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So the&amp;nbsp;primary issue with expecting Native Clients to handle route information properly... When&amp;nbsp;&lt;EM&gt;most&lt;/EM&gt; clients (95%+) are unable to understand received route information they will generally fall-back to their default of 0.0.0.0/0, sending everything through the established tunnel. Just to verify, are you seeing the native clients route&amp;nbsp;&lt;EM&gt;everything&lt;/EM&gt; through the tunnel or are you getting &amp;nbsp;&lt;EM&gt;nothing&lt;/EM&gt; through the tunnel?&lt;/P&gt;&lt;P&gt;This has always been a downside of using native clients, and why most vendors have moved away from them. You simply can't anticipate how others will implement things so stuff will always break as one side or the other makes changes. Now that most vendors are using agents it's even less of a concern for most, as most people will never even notice if it's broken. This essentially boils down to the fact that IPSec implementations&amp;nbsp;really don't follow a set standard, they never have.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 14:06:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230344#M66218</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-09-11T14:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA on both portal and gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230445#M66220</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;They don't route everything but they do route too much but they also don't route the network they were created to access. But the main point that I am trying to get across to the users who don't want the client for some reason, can't expect it to work the same as the globalprotect.&amp;nbsp; If it sheds any light we are talk about mac users LOL &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 14:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2fa-on-both-portal-and-gateway/m-p/230445#M66220</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-11T14:25:12Z</dc:date>
    </item>
  </channel>
</rss>

