<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication policy for RDP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234685#M67275</link>
    <description>&lt;P&gt;Yeah I did. But didn't see any traffic on that port. Also didn't see that traffic in packet caprure I did on the PC from where I was testing.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 06:12:23 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2018-10-10T06:12:23Z</dc:date>
    <item>
      <title>Authentication policy for RDP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234378#M67188</link>
      <description>&lt;P&gt;I have succesfuly implemented auth policy for http and https (with decryption).&lt;/P&gt;&lt;P&gt;But I can't get it to work for RDP. Yes, I know I need GP client for non-browser protocols.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer is using MS MFA server. As it's not supported by PA as MFA server we configured it as Radius server.&lt;/P&gt;&lt;P&gt;I have auth profile which uses Radius server profile towards MS MFA.&lt;/P&gt;&lt;P&gt;Captive portal is enabled, in redirect mode, redirects to internal interface of PA, response pages are enabled in mgmt profile, and it uses configured auth profile for MFA (Radius).&lt;/P&gt;&lt;P&gt;We have an auth policy for any service to single server with authenticaon method web-form and same authentication profile for &lt;SPAN&gt;MFA&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;R&lt;/SPAN&gt;&lt;SPAN&gt;adius).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've&amp;nbsp; set Enable Inbound Authentication Prompts from MFA Gateways to Yes and I entered both PA interface with captive portal and MFA server address as&amp;nbsp;Trusted MFA Gateways.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we try a RDP connection; we see the connection in session browser, details say that it hits the correct auth rule,&amp;nbsp;has value False for captive portal and nothing happens. Session isn't logged in traffic log, no new entries in authentication logs, nothing in authd.log.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet capture&amp;nbsp; shows succesful TCP 3 way handshake and reset form server soon after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 08:10:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234378#M67188</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-10-08T08:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication policy for RDP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234657#M67269</link>
      <description>&lt;P&gt;Did you open udp port 4501 on the host firewall of the host running the GP client? Only with that port open on the host will you see the authentication prompt pop up from the GP client. I had to do this for SSH auth policy. The service in the auth policy will be the TCP RDP port.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 22:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234657#M67269</guid>
      <dc:creator>MichaelMelone</dc:creator>
      <dc:date>2018-10-09T22:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication policy for RDP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234685#M67275</link>
      <description>&lt;P&gt;Yeah I did. But didn't see any traffic on that port. Also didn't see that traffic in packet caprure I did on the PC from where I was testing.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 06:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-policy-for-rdp/m-p/234685#M67275</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-10-10T06:12:23Z</dc:date>
    </item>
  </channel>
</rss>

