<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect 2FA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236416#M67751</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56459"&gt;@Filip_Fronczak&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things that I can think of that could be causing this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Save User Credentials - Must be set to no, or saving username only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSO must be disabled in the App configuration. (portals -&amp;gt; agent -&amp;gt; app)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the authentication profile for the gateway set to the one with the RADIUS server profile attached?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Luke.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 21 Oct 2018 19:48:24 GMT</pubDate>
    <dc:creator>LukeBullimore</dc:creator>
    <dc:date>2018-10-21T19:48:24Z</dc:date>
    <item>
      <title>GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236374#M67745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PaloAlto VM-100 8.0.13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been trying to add 2FA to our GlobalProtect Gateway. I've followed the instructions described here:&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/set-up-two-factor-authentication/enable-two-factor-authentication-using-one-time-passwords-otps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Probably I've must have done something wrong, because I am prompted twice to enter the LDAP (AD) password insted of LDAP and RADIUS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please point me to where I made the mistake?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you a lot.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 15:03:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236374#M67745</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-21T15:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236416#M67751</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56459"&gt;@Filip_Fronczak&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things that I can think of that could be causing this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Save User Credentials - Must be set to no, or saving username only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSO must be disabled in the App configuration. (portals -&amp;gt; agent -&amp;gt; app)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the authentication profile for the gateway set to the one with the RADIUS server profile attached?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Luke.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 19:48:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236416#M67751</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-21T19:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236417#M67752</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56459"&gt;@Filip_Fronczak&lt;/a&gt;&lt;/P&gt;&lt;P&gt;What does your RADIUS server require for authentication? Only the second factor or username, password and second factor?&lt;/P&gt;&lt;P&gt;Do you want wo use LDAP on the portal and RADIUS on the gateway or how exactly did you configure the authentication?&lt;/P&gt;&lt;P&gt;(Did you commit your changes os is there the little chance that you still have LDAP on portal and gateway and because of that you're asked twice for AD credentials?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 20:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236417#M67752</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-21T20:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236420#M67755</link>
      <description>&lt;P&gt;I've made some progres - I've changed the order of authentication profiles in: GlobalProtect Gateway Configuration/Authentication.&lt;/P&gt;&lt;P&gt;If I put the RADIUS first and AD second it asks me first for the AD password and then for the RADIUS OTP code.&lt;/P&gt;&lt;P&gt;Strange, but it is like this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I have another problem. I enter the AD password and it gets accepted then I enter the OTP code and I get prompted again and again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the system log:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2018/10/22 00:07:49,,globalprotectgateway-auth-fail,GP-Gateway-N,0,0,general,informational,"GlobalProtect gateway user authentication failed. Login from: nn.nn.nn.nn, Source region: xx, User name: xxxx, Client OS version: Microsoft Windows 10 Pro , 64-bit, Reason: &lt;STRONG&gt;Authentication failed: Timeout&lt;/STRONG&gt; , Auth type: profile.",3035522,0x0,0,0,0,0,,PA-VM-01&lt;BR /&gt;2018/10/22 00:07:04,,globalprotectportal-config-succ,Portal1,0,0,general,informational,"GlobalProtect portal client configuration generated. Login from: nn.nn.nn.nn, Source region: xx, User name: xxxx, Config name: Portal_Agent.",3035517,0x0,0,0,0,0,,PA-VM-01&lt;BR /&gt;2018/10/22 00:07:04,,globalprotectportal-auth-succ,Portal1,0,0,general,informational,"&lt;STRONG&gt;GlobalProtect portal user authentication succeeded&lt;/STRONG&gt;. Login from: nn.nn.nn.nn, Source region: xx, User name: xxxx, Auth type: profile.",3035516,0x0,0,0,0,0,,PA-VM-01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time in the SafeNet Auth. Service (OTP) I have a successfull authentication:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" cellspacing="0" cellpadding="2"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2018-10-22 00:07:24&lt;/TD&gt;&lt;TD&gt;xxxx&lt;/TD&gt;&lt;TD&gt;Authentication&lt;/TD&gt;&lt;TD&gt;Success&lt;/TD&gt;&lt;TD&gt;MobilePASS&lt;/TD&gt;&lt;TD&gt;06104216&lt;/TD&gt;&lt;TD&gt;192.168.2.192&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 22:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236420#M67755</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-21T22:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236422#M67756</link>
      <description>&lt;P&gt;Never mind. The last problem was my mistake. I have changed the secret in NPS and forgot to click OK.&lt;/P&gt;&lt;P&gt;Everything works fine now.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 22:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/236422#M67756</guid>
      <dc:creator>Filip_Fronczak</dc:creator>
      <dc:date>2018-10-21T22:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect 2FA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/389248#M90611</link>
      <description>&lt;P&gt;Just in case anyone wants to know, I have written a blog about this topic here:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_3" class="page-link lia-link-navigation lia-custom-event" href="https://live.paloaltonetworks.com/t5/blogs/dotw-mfa-and-2fa-for-gp-and-ngfw/ba-p/359778" target="_blank"&gt;DOTW: MFA and 2FA for GP and NGFW&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be sure to check it out.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 22:11:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-2fa/m-p/389248#M90611</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-04T22:11:29Z</dc:date>
    </item>
  </channel>
</rss>

