<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2-Factor Authentication for Admin Login in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/249017#M70841</link>
    <description>&lt;P&gt;Correct, this is supported in 8.1.&lt;/P&gt;&lt;P&gt;See the updated page:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-server-profiles-multi-factor-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-server-profiles-multi-factor-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For the following authentication use cases, the firewall integrates with multi-factor authentication (MFA) vendors using RADIUS and SAML:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Remote user authentication through GlobalProtect™ portals and gateways.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;Administrator authentication in the PAN-OS and Panorama™ web interface.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Authentication through Authentication policy.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Wed, 06 Feb 2019 14:32:36 GMT</pubDate>
    <dc:creator>ksalustro</dc:creator>
    <dc:date>2019-02-06T14:32:36Z</dc:date>
    <item>
      <title>2-Factor Authentication for Admin Login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226782#M65289</link>
      <description>&lt;P&gt;HI all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is likely to have been asked before, but a search of the Live! forums didn't turn up anything relevant&lt;/P&gt;&lt;P&gt;As part of security best practices in my organisation, I'm looking to enable 2FA (via DUO) on the&amp;nbsp;admin web interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the instructions for adding 2FA to user browsing via Captive Portal, and for adding 2FA to GlobalProtect connections, but there doesn't seem to be anything for the admin interface. I noticed on &lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/device/device-server-profiles-multi-factor-authentication" target="_self"&gt;this page&lt;/A&gt; it says "&lt;SPAN&gt;The firewall supports MFA only for end users, not firewall administrators".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just wanted to check with anyone that can confirm, is that a universal rule for PAN-OS (as of 8.0)? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There is no support for 2FA on the admin login at present?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thinking about the&amp;nbsp;flow of an admin login, I'm not sure I can see how it would work.&amp;nbsp;You can't really&amp;nbsp;use source &amp;amp; dest objects to specify the admin interface when defining an Authentication Policy, to my knowledge. But if this can be done, I'd appreciate any instructions&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm using a PA-220 on PAN-OS 8.1.2, with administrator logins stored in Active Directory and an&amp;nbsp;LDAP-based Authentication Profile to secure logins.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 04:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226782#M65289</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-11T04:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: 2-Factor Authentication for Admin Login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226798#M65293</link>
      <description>&lt;P&gt;Hi @Retired Member&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know MFA with the PAN-OS integrated MFA provider this isn't possible. Only with RADIUS or SAML it is possible to secure the adminlogin with a multi factor authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 09:28:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226798#M65293</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-08-11T09:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2-Factor Authentication for Admin Login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226800#M65295</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Duo has a &lt;A href="https://duo.com/docs/radius" target="_self"&gt;proxy application&lt;/A&gt;&amp;nbsp;that can be installed on-prem, act as a RADIUS server for authentication and lookup to our Active Directory. I'll give this a go and see if it works as a 2FA solution for admin login.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 11:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/226800#M65295</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-11T11:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2-Factor Authentication for Admin Login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/249017#M70841</link>
      <description>&lt;P&gt;Correct, this is supported in 8.1.&lt;/P&gt;&lt;P&gt;See the updated page:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-server-profiles-multi-factor-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-server-profiles-multi-factor-authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For the following authentication use cases, the firewall integrates with multi-factor authentication (MFA) vendors using RADIUS and SAML:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Remote user authentication through GlobalProtect™ portals and gateways.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;&lt;STRONG&gt;Administrator authentication in the PAN-OS and Panorama™ web interface.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="p"&gt;Authentication through Authentication policy.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 06 Feb 2019 14:32:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-factor-authentication-for-admin-login/m-p/249017#M70841</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2019-02-06T14:32:36Z</dc:date>
    </item>
  </channel>
</rss>

