<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Require authentication via global protect when connecting to data center resources in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259455#M73573</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it is a pretty big challenege. I'm familiar with most of Palo Alto as I spent my first couple of months in this job diving in and learning our setup and getting familiar with the device. We intend to use freeRADIUS, which we use for authenticating admin access into our devices, for the 2FA portion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for those links, I'll be diving into them shortly.&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 19:55:50 GMT</pubDate>
    <dc:creator>bhughesiii</dc:creator>
    <dc:date>2019-05-01T19:55:50Z</dc:date>
    <item>
      <title>Require authentication via global protect when connecting to data center resources</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259136#M73482</link>
      <description>&lt;P&gt;In an attempt to secure connections to production resources. I would like to implement a policy that if you are for instance using SSMS to connect from one location to a database in the data center, that you first have to authenticate via global protect client using two factor authentication before you can connect to said resource.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any guidance would be greatly appreciated and any requests for more information will be answered as quickly as I can.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 19:51:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259136#M73482</guid>
      <dc:creator>bhughesiii</dc:creator>
      <dc:date>2019-04-29T19:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Require authentication via global protect when connecting to data center resources</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259354#M73541</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112122"&gt;@bhughesiii&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Usually GlobalProtect connections are terminated in their own zone on the firewall. If that's the case in your environment, you would simply modify the existing security policies so that only the GlobalProtect zone is allowed access to your data center resources and let everything else hit the interzone-default policy or a specific deny rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 22:08:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259354#M73541</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-30T22:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Require authentication via global protect when connecting to data center resources</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259428#M73567</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, I'll look into that. This is my first rodeo with Palo Alto and firewalls in general so somethings like this are slightly over my head.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 16:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259428#M73567</guid>
      <dc:creator>bhughesiii</dc:creator>
      <dc:date>2019-05-01T16:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Require authentication via global protect when connecting to data center resources</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259440#M73570</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/112122"&gt;@bhughesiii&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For a start with paloalto you chose a challenging project &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What you are asking for is possible. To start with this read the following documents:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/user-id/map-ip-addresses-to-users/map-ip-addresses-to-usernames-using-captive-portal/configure-captive-portal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/globalprotect-features/authentication-policy-and-multi-factor-authentication-for-globalprotect" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-new-features/globalprotect-features/authentication-policy-and-multi-factor-authentication-for-globalprotect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/configure-globalprotect-to-facilitate-multi-factor-authentication-notifications.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/authentication/configure-globalprotect-to-facilitate-multi-factor-authentication-notifications.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Depending on the authentication method and if you use MFA GlobalProtect will guide the user through the authentication process or display an URL that leads to the captive portal website where the user is required to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 19:31:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259440#M73570</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-05-01T19:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Require authentication via global protect when connecting to data center resources</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259455#M73573</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it is a pretty big challenege. I'm familiar with most of Palo Alto as I spent my first couple of months in this job diving in and learning our setup and getting familiar with the device. We intend to use freeRADIUS, which we use for authenticating admin access into our devices, for the 2FA portion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for those links, I'll be diving into them shortly.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 19:55:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/require-authentication-via-global-protect-when-connecting-to/m-p/259455#M73573</guid>
      <dc:creator>bhughesiii</dc:creator>
      <dc:date>2019-05-01T19:55:50Z</dc:date>
    </item>
  </channel>
</rss>

