<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authetication override in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232030#M66600</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes just to make a better user experience so they don't have to log in twice and no I they would not be logged in for 7 days&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks like generate cookie on the portal and accept onthe gateway is the best way to go for me. I have both radius and OTP set on both the portal and the gateway. I have both native clients and globalprotect clients using the VPN.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 13:20:47 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-09-24T13:20:47Z</dc:date>
    <item>
      <title>authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230911#M66320</link>
      <description>&lt;P&gt;Why is it necessary to enter "generate cookie for authentication override and accept cookie for the authentication override on both the portal and gateway? I would think it would make more sense to select&amp;nbsp;&lt;SPAN&gt;generate cookie for authentication override on the portal and&amp;nbsp;accept cookie for the authentication override&amp;nbsp; on the gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am also not sure what you have to put authentication method on both the portal and the gateway.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 20:04:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230911#M66320</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-14T20:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230938#M66325</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you only need the cookie for a better user experience during &lt;EM&gt;one&amp;nbsp;&lt;/EM&gt;login, then it is enough if you only generate the cookie ond the portal and accept it on the gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have for example the requirement that a login should be valid for 7 days so that the user only has to log in again if he did not connect for 7 days, then I would also generate the cookies on the gateway. This way the cookie will also be renewed in case the portal is not available. Also because of that reason (portal not available) I would configure portal and gateway with the same authentication - to keep the authentication as you need it also in cases where a client (for whatever reason) skips the portal and connects to the gateway directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 23:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230938#M66325</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-09-14T23:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230959#M66330</link>
      <description>&lt;P&gt;Yes as per mr remo....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;generate on portal and accept on gateway.&lt;/P&gt;&lt;P&gt;whatever auth you have on the portal, set same on the gateway.&lt;/P&gt;&lt;P&gt;cookie overide will prevent user having to authenticate again on gateway but needs to be there if portal is ever unavailablle&lt;/P&gt;&lt;P&gt;because client will use cached portal info and connect directly to the gateway(s) without a cookie.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pretty much repeated what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;already stated but im gonna post anyhows...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Sep 2018 17:16:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/230959#M66330</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-15T17:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232030#M66600</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes just to make a better user experience so they don't have to log in twice and no I they would not be logged in for 7 days&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks like generate cookie on the portal and accept onthe gateway is the best way to go for me. I have both radius and OTP set on both the portal and the gateway. I have both native clients and globalprotect clients using the VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 13:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232030#M66600</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-24T13:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232096#M66621</link>
      <description>&lt;P&gt;Bingo!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 16:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232096#M66621</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-24T16:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232290#M66645</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured this and it worked just the way I wanted wooohooo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;generate on portal and accept on gateway.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232290#M66645</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-25T15:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: authetication override</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232300#M66648</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Congratulations, you have earned a new badge...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="newbadge.png" style="width: 241px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/16765i1D5665DA7E18C7CF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="newbadge.png" alt="newbadge.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:22:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authetication-override/m-p/232300#M66648</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-25T15:22:13Z</dc:date>
    </item>
  </channel>
</rss>

