<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Purpose of Authen Profile under Global Protect Gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238474#M68316</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured MFA using CP and using RSA as Second&amp;nbsp; authen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Authen--------------Radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Authen ----------------Radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Device&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP&amp;nbsp; -&amp;nbsp; Authen ---------RSA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why we need Authen profile under Gateway??????????&lt;/P&gt;&lt;P&gt;should Authen profile under Portal and Gateway have to be same?????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why we use same authen Radius on both&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Nov 2018 04:13:37 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2018-11-03T04:13:37Z</dc:date>
    <item>
      <title>Purpose of Authen Profile under Global Protect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238474#M68316</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured MFA using CP and using RSA as Second&amp;nbsp; authen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Authen--------------Radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Authen ----------------Radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under Device&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP&amp;nbsp; -&amp;nbsp; Authen ---------RSA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why we need Authen profile under Gateway??????????&lt;/P&gt;&lt;P&gt;should Authen profile under Portal and Gateway have to be same?????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why we use same authen Radius on both&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 04:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238474#M68316</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-03T04:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Authen Profile under Global Protect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238497#M68322</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would give you the possibility to assign different authentication profiles for portal and gateway, but as you are using the same one for both, it makes sure that users alwaya have to login with MFA (just in case the access to the portal isn't possible for whatever reason). In this situation with a not working portal the GP clients will try to connect ditectly to the gateway.&lt;/P&gt;&lt;P&gt;So you have now secured the access with MFA, but to make the login process for the users a little easier (so that they don't need to log in twice for establishing the connection) you should configure authentication override with a cookie lifetime of 1 minute. This way when everything works as expected a user is required to do the MFA authentication only once.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 15:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238497#M68322</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-03T15:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Authen Profile under Global Protect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238498#M68323</link>
      <description>&lt;P&gt;Hi Remo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Always good to get reply from you.&lt;/P&gt;&lt;P&gt;I did not understand this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;should configure authentication override with a cookie lifetime of 1 minute. This way when everything works as expected a user is required to do the MFA authentication only once.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can you please explain this in more detail?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 15:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238498#M68323</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-11-03T15:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Authen Profile under Global Protect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238503#M68326</link>
      <description>&lt;P&gt;--&amp;gt;&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/about-globalprotect-user-authentication/how-does-the-agent-or-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentication/about-globalprotect-user-authentication/how-does-the-agent-or-app-know-what-credentials-to-supply/cookie-authentication-on-the-portal-or-gateway&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article explain the use of cookies for authentication override and the general purpose of these. The time these cookies are valid can go up to a year but if you only want to improve the user experience while maintaining a secure as possible authentication you should configure the lifetime to only 1 minute. This way the cookie can only be used for this one minute and connection attempts after this minute need to do again the full MFA authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 20:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/purpose-of-authen-profile-under-global-protect-gateway/m-p/238503#M68326</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-11-03T20:56:29Z</dc:date>
    </item>
  </channel>
</rss>

