<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect MFA Vendor Support in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/289472#M76989</link>
    <description>&lt;P&gt;can someone please explain below in more detail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you've said, through RADIUS you can integrate with any vendor (from firewall perspective, this is RADIUS only, it doesn't care what's happening in the background, just waiting for Access Accept/Reject message).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Sep 2019 15:30:28 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-09-22T15:30:28Z</dc:date>
    <item>
      <title>Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282015#M76028</link>
      <description>&lt;P&gt;I am a bit confused with the MFA vendor supported by the firewall, because the Compatibility Matrix says that&amp;nbsp; MFA server profile is not supported for Global Protect?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.html#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am aware that any MFA vendor can be configure over Radius Server, but presuming that we don’t use Radius ,&amp;nbsp; and we get one 4 supported vendors, e.g. RSA SecureID, can client–based and clientless GlobalProtect be configured with LDAP and 2FA?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 12:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282015#M76028</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-08-09T12:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282145#M76035</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes this should be possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/authentication/configure-globalprotect-to-facilitate-multi-factor-authentication-notifications.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/authentication/configure-globalprotect-to-facilitate-multi-factor-authentication-notifications.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 19:43:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282145#M76035</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-08-09T19:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282244#M76056</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;Thank you for responding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The article is not quite clear, but it is in fact hinting (under Step1) that only Radius based authentictaion is possible:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"If you are using two-factor authentication with GlobalProtect to authenticate to the gateway or portal,&lt;U&gt; a RADIUS server profile is required&lt;/U&gt;. If you are using GlobalProtect to notify the user about an authentication policy match (UDP message), a Multi Factor Authentication server profile is sufficient."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will be great if someone tried it and can share experience. I don't want to advise the customer to sign&amp;nbsp; up for one of 4 vendors, if then they will not work GlobalProtect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 07:54:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282244#M76056</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-08-12T07:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282656#M76114</link>
      <description>&lt;P&gt;Direct MFA integration is meant to be used with Authentication Policy only (Captive Portal). If you are creating Authentication Profile and go under "Factor" you'll see a note stating: "&lt;SPAN&gt;The factors below are used only for Authentication Policy" (and the Factors are referencing MFA profiles).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you've said, through RADIUS you can integrate with any vendor (from firewall perspective, this is RADIUS only, it doesn't care what's happening in the background, just waiting for Access Accept/Reject message).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A lot of confusion comes from the fact that MFA is used in Authentication Policies, and Authentication Policies if triggered for non-web-based traffic can trigger user notification through GP client (GP used only to relay the message from the firewall that there was an access attempt on port x, when firewall can't redirect the user to captive portal - for example ssh traffic).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 06:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282656#M76114</guid>
      <dc:creator>nimark</dc:creator>
      <dc:date>2019-08-14T06:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282680#M76118</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/6997"&gt;@nimark&lt;/a&gt;&amp;nbsp;Thank you, this calrifies it better&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 08:08:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/282680#M76118</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-08-14T08:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/289472#M76989</link>
      <description>&lt;P&gt;can someone please explain below in more detail&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you've said, through RADIUS you can integrate with any vendor (from firewall perspective, this is RADIUS only, it doesn't care what's happening in the background, just waiting for Access Accept/Reject message).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 15:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/289472#M76989</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-09-22T15:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect MFA Vendor Support</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/428265#M94692</link>
      <description>&lt;P&gt;This post has long been solved, but for future onlookers this table is awesome to see what use cases and protocols can be used for MFA support.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.html" target="_blank"&gt;https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 22:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-mfa-vendor-support/m-p/428265#M94692</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-08-21T22:16:28Z</dc:date>
    </item>
  </channel>
</rss>

