<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247797#M70507</link>
    <description>&lt;P&gt;Thanks, I guess I need to try this out.&lt;/P&gt;&lt;P&gt;Problem is the connect mode - I would need userlogon for sso and on demand for external auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check this out and call out for our Palo SE if it doesn't work - this should be a common setup I assumed&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jan 2019 15:40:38 GMT</pubDate>
    <dc:creator>Chacko42</dc:creator>
    <dc:date>2019-01-28T15:40:38Z</dc:date>
    <item>
      <title>Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247415#M70396</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my customer wants to use Globalprotect for on demand login with a MFA radius server.&lt;/P&gt;&lt;P&gt;Everything fine - configured is and it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, we want to use Globalprotect&amp;nbsp;as an&amp;nbsp;internal UserID source.&lt;/P&gt;&lt;P&gt;So every GP-Client needs to do Userlogon SSO when connected to internal network (should be completely transparent to the users). But only on demand, the users should decide to connect to GP-Portal to initiate a VPN connection to external gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because we cannot expect from the endusers, to choose this GP-Portal for VPN connect, and the other one for internal GW connection, we need to use only one portal for this need.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that possible? How to configure it? Auth Sequence with first SSO, second RADIUS? How to do User-Logon SSO when connected interanl and only on demand when connected to external ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 20:13:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247415#M70396</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-01-24T20:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247450#M70403</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check out these videos, I think they are what you are looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm2uCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm2uCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 20:56:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247450#M70403</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-01-24T20:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247552#M70422</link>
      <description>&lt;P&gt;Have you looked into using regions in your external gateway config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regions take priority over "Gateway Priority"&amp;nbsp; so add all internal gateways to your portal config but add regions to the internal ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Available on 8.sumfink&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 08:29:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247552#M70422</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-25T08:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247555#M70423</link>
      <description>&lt;P&gt;Hmmm... just re read your post...&amp;nbsp;&amp;nbsp; so you want users to auto connect when on the lan but on demand connection when not on the lan....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is before you even consider what auth methods to use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i dont get it...&amp;nbsp; sorry. would you not be better off with captive portal when on the lan?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 09:29:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247555#M70423</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-25T09:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247583#M70431</link>
      <description>&lt;P&gt;Well, we want to user internal Globalprotect to get more resilient UserID information and to prevent policiy-mismatches, when the users aren't spamming any Kerberors tickets - so internal Globalprotect with mode "User Login" and Kerberos SSO would be the way to go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the same users/devices should be allowed to do internet stuff when beeing external and they should decide when to use VPN, so this is a thing for "on demand" mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We cannot expect, that the users will be happy with using different portals - that must work transparently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 14:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247583#M70431</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-01-25T14:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247598#M70433</link>
      <description>&lt;P&gt;I can't think of a solution to this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;almost... as you can have regional gateways for different auths depending on your location and you could have 2 portals, one internal and one external and let your DNS point you to the correct one..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but even then, you will need to manually connect to the internal portal to get the setting put back to always on...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 15:42:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247598#M70433</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-25T15:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247797#M70507</link>
      <description>&lt;P&gt;Thanks, I guess I need to try this out.&lt;/P&gt;&lt;P&gt;Problem is the connect mode - I would need userlogon for sso and on demand for external auth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check this out and call out for our Palo SE if it doesn't work - this should be a common setup I assumed&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 15:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/247797#M70507</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-01-28T15:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/395101#M91236</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any news about this setup? I have exactly the same use case to solve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:56:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/395101#M91236</guid>
      <dc:creator>Jan_Linhart</dc:creator>
      <dc:date>2021-03-31T08:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect: Externel On Demand logon with RADIUS, internal SSO</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/395111#M91238</link>
      <description>&lt;P&gt;Hi Jan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;internal host detection won't work with on demand setup.&lt;/P&gt;&lt;P&gt;So the customer needs to choose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my point of view, always on is the only secure version and on-demand should be avoided.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 09:35:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-externel-on-demand-logon-with-radius-internal-sso/m-p/395111#M91238</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2021-03-31T09:35:54Z</dc:date>
    </item>
  </channel>
</rss>

