<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP- AD auth and SMS through ext radius in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289471#M76988</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using MFA with RSA and on Portal and Gateway I have same authen profile which is AD then on Authen policy&amp;nbsp; i choose&lt;/P&gt;&lt;P&gt;RSA and it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems in out setup when user logins to PC he also gets login to GP client automatically as it is always on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Sep 2019 14:59:58 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-09-22T14:59:58Z</dc:date>
    <item>
      <title>GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/286966#M76667</link>
      <description>&lt;P&gt;Hi all ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone accomplished to authenticate external users 1st with AD through LDAP profile and then SMS through radius to another server ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess 1st authentication will done in the portal and SMS auth profile can be added on the gateway&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 11:54:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/286966#M76667</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-06T11:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287001#M76670</link>
      <description>&lt;P&gt;That would work but the only issue would be if the portal was unavailable...&amp;nbsp; &amp;nbsp;the GP client would used last cached gateway info and user would only require SMS auth to gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2019 15:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287001#M76670</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-06T15:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287179#M76682</link>
      <description>&lt;P&gt;thank you , so if I want to have the 2nd factor authentication like mentioned how is going to be configured ?&amp;nbsp; 2 auth profiles in one auth sequence attached to both portal and gateway ?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2019 12:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287179#M76682</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-07T12:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287181#M76684</link>
      <description>&lt;P&gt;No, this cannot be done, the auth sequence will finish when the first in the list succeeds.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the closest option without using a purpose built MFA is LDAP or Radius combined with certificate..&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2019 13:32:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/287181#M76684</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-07T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289332#M76959</link>
      <description>&lt;P&gt;Can I have LDAP profile to authenticate users against AD for the portal and then use authentication profile with RADIUS for SMS token delivery for the gateway ?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 15:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289332#M76959</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-20T15:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289366#M76963</link>
      <description>&lt;P&gt;Yes you can do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but just be aware... &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the portal ever becomes unavailable the local client will use the last known portal config and attempt to connect to the gateway directly, so only passcode will be required... &amp;nbsp; &amp;nbsp; this may also be confusing for users as they will not know if to use password or passcode... &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why do you feel you need both ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does your sms passcode also require a username and PIN?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 17:28:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289366#M76963</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-20T17:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289367#M76964</link>
      <description>&lt;P&gt;I have multiple gateways and that means that Firewalls that have the portals they don't have the gateways and the firewalls with the gateways they don't have any portals .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to attach LDAP-AD profile that works in the portal and the profile for the SMS provider to the gateways&amp;nbsp; which I have configured the firewalls to send vs source-ip only. But doesn't work because it seems that app sends the ad password as passcode since I get SMS that my account is locked but if I do the opposite and I use the SMS auth in the Portal and the LDAP-AP profile in the gateway then I get SMS , I put that since I am getting prompted and then auth fail with no reason but I suspect that this SMS passcode is being used in the gateway .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 17:32:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289367#M76964</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-20T17:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289386#M76965</link>
      <description>&lt;P&gt;What do you have in network/portal/config/authentication/save user credentials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 18:49:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289386#M76965</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-20T18:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289439#M76976</link>
      <description>&lt;P&gt;I had save user name only and I tried also with no.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2019 17:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289439#M76976</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-21T17:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289467#M76984</link>
      <description>&lt;P&gt;So in this config Portal and Gateway auth profile should match?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 14:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289467#M76984</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-09-22T14:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289470#M76987</link>
      <description>&lt;P&gt;No , because user should put one time user/pass that will be checked against AD and then on the gateway I would like user to put one time password through another AD that delivers the SMS to user .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I made it work with Portal SMS and gateway AD credentials but I get 3 times to provide password and two of them is AD credentials .&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 14:54:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289470#M76987</guid>
      <dc:creator>GeorgiosFakis</dc:creator>
      <dc:date>2019-09-22T14:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289471#M76988</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using MFA with RSA and on Portal and Gateway I have same authen profile which is AD then on Authen policy&amp;nbsp; i choose&lt;/P&gt;&lt;P&gt;RSA and it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems in out setup when user logins to PC he also gets login to GP client automatically as it is always on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 14:59:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/289471#M76988</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-09-22T14:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: GP- AD auth and SMS through ext radius</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/317649#M81643</link>
      <description>&lt;P&gt;Hi Georgios. At the end it does work? I have a similar issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I probe the integration between Palo Alto - Google Authenticator trough RADIUS and it works perfectly. But now I need to integrate the same with LDAP in the entire authentication process. So customer wants:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP user opens and authenticate - User Mapping with LDAP Profile - Sends to user the authcode - login with the token&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't fin the configuration process. Can you help me?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 11:41:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ad-auth-and-sms-through-ext-radius/m-p/317649#M81643</guid>
      <dc:creator>RPerez11</dc:creator>
      <dc:date>2020-03-20T11:41:59Z</dc:date>
    </item>
  </channel>
</rss>

