<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client Authentication Sequence only works for 1st item in the list in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256746#M72841</link>
    <description>&lt;P&gt;Auth sequence is &amp;nbsp;simply a list of possible auth services. It will run down the list until one is accepted.&lt;/P&gt;&lt;P&gt;it is not designed for MFA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could look into Globalprotect MFA, there are plenty of links available, i use cert and Ldap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could just have local for portal and ldap for gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;although this could be less secure if portal is down and client uses cached gateway address.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2019 06:04:22 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-04-09T06:04:22Z</dc:date>
    <item>
      <title>Client Authentication Sequence only works for 1st item in the list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256738#M72840</link>
      <description>&lt;P&gt;I configured Client Authentication Sequence for both GlobalProtect Portal and Gateway for both LDAP and local database.&amp;nbsp; For some reason, only the first item in the list works.&amp;nbsp; It does not seem to try the rest of the sequences in the list. If LDAP is first in the list, then LDAP authentication works but not Local database.&amp;nbsp;&amp;nbsp; If Local databse is first in the list, then local database authentication works but not LDAP authentication.&amp;nbsp; What could be causing this?&amp;nbsp; This is 9.0 version.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 05:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256738#M72840</guid>
      <dc:creator>rhap4boy</dc:creator>
      <dc:date>2019-04-09T05:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication Sequence only works for 1st item in the list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256746#M72841</link>
      <description>&lt;P&gt;Auth sequence is &amp;nbsp;simply a list of possible auth services. It will run down the list until one is accepted.&lt;/P&gt;&lt;P&gt;it is not designed for MFA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could look into Globalprotect MFA, there are plenty of links available, i use cert and Ldap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could just have local for portal and ldap for gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;although this could be less secure if portal is down and client uses cached gateway address.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 06:04:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256746#M72841</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-09T06:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication Sequence only works for 1st item in the list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256813#M72861</link>
      <description>&lt;P&gt;Not trying to do multiple factor authentication. &amp;nbsp;I simply want to two different methods of login in. &amp;nbsp;Use either local database or LDAP. &amp;nbsp;It suppose to take the login name and password and try each of the method in sequence until one login right?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 14:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256813#M72861</guid>
      <dc:creator>LCMember2099</dc:creator>
      <dc:date>2019-04-09T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication Sequence only works for 1st item in the list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256826#M72865</link>
      <description>&lt;P&gt;Yes that is what should happen, sorry for the confusion, i thought you were trying to use 2 logins...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it say in monitor/system that it failed on just the first, i can try this on my test boxes tomorrow&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2019 17:43:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/256826#M72865</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-09T17:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Client Authentication Sequence only works for 1st item in the list</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/257175#M72954</link>
      <description>&lt;P&gt;i have ldap server 1, ldap server 2 and local database in my sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can login with either my local account or my ldap account so not sure whats going wrong for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i did confirm the sequence was working with monitor/packet capture to see a request going to all servers.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 08:26:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/client-authentication-sequence-only-works-for-1st-item-in-the/m-p/257175#M72954</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-11T08:26:17Z</dc:date>
    </item>
  </channel>
</rss>

