<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect SAML Metadata in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/374584#M89074</link>
    <description>&lt;P&gt;Just fyi, I have this working in an Azure environment, with a private IP on the virtual firewall in Azure, and didn't run into this problem... SAML works fine to Azure.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 21:21:30 GMT</pubDate>
    <dc:creator>ksalustro</dc:creator>
    <dc:date>2020-12-15T21:21:30Z</dc:date>
    <item>
      <title>GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311592#M80627</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured Azure SAML SSO for GlobalProtect. When I try to export Metadata from PaloAlto FW for&amp;nbsp;global-protect service, there is a mandatory section to select which virtual system. But in my case, there is no virtual system to select from. I am not sure what's the issue. Any idea what's going on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SAML metadata.PNG" style="width: 982px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23995iEE2AF4A02A0974D8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SAML metadata.PNG" alt="SAML metadata.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2020 21:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311592#M80627</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-02-17T21:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311620#M80632</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128041"&gt;@Sahir_Algharibih&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see default vsys in drop-down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 02:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311620#M80632</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-02-18T02:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311624#M80634</link>
      <description>&lt;P&gt;There is nothing in the drop-down. It’s empty. That’s why I am asking to see if anyone had such issue from before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 02:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/311624#M80634</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-02-18T02:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/314946#M81182</link>
      <description>&lt;P&gt;Hi Sahir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you get ever get a fix for this issue? I have exactly the same problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 17:02:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/314946#M81182</guid>
      <dc:creator>MartinLuff</dc:creator>
      <dc:date>2020-03-06T17:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315091#M81201</link>
      <description>&lt;P&gt;i had same issue while generating metadata xml file from palo alto firewall. delete saml profile and create it again worked for me. it's showing vsys1&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 15:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315091#M81201</guid>
      <dc:creator>adityajoshi</dc:creator>
      <dc:date>2020-03-07T15:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315096#M81202</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129521"&gt;@adityajoshi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did delete and created the profile several times, still same issue. I think SAML is not working for me, because of the way our Azure environment setup, where the firewall is pulling a private IP address from Azure DHCP &amp;amp; that is being Natted by Azure, where we have no control over it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was your setup in Azure too? if so, can you please provide the steps you used to get it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sahir&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 15:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315096#M81202</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-03-07T15:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315123#M81211</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/93633"&gt;@MartinLuff&lt;/a&gt;, please see my answer to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/129521"&gt;@adityajoshi&lt;/a&gt;&amp;nbsp;below&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 19:25:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/315123#M81211</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-03-07T19:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320039#M82000</link>
      <description>&lt;P&gt;I tried deleting it multiple times, created a new SAML Server profile, new auth profile and still nothing. Anyone know what it could be?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 15:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320039#M82000</guid>
      <dc:creator>Eric_Rivera</dc:creator>
      <dc:date>2020-04-01T15:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320066#M82007</link>
      <description>&lt;P&gt;Is your GP solution in Azure or local?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 17:10:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320066#M82007</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-04-01T17:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320068#M82008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the issue is the way Azure environment is built. From experience, you can't get SAML running because your Azure FW is using a private IP address from a DHCP server, and that private IP get's natt'ed by Azure on your behalf. All that, causes it to break. I've tested the same SAML configuration on a local firewall, and it worked first time. Therefore, Azure is no longer an option for our GP solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 17:14:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/320068#M82008</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-04-01T17:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/322654#M82512</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm currently experiencing this on an on-premise PA-220 firewall. When you want to export the Metadata file from the firewall, the authentication profile is there already. However, clicking the VSYS drop-down gives no value and so the 'OK' button is greyed out.&lt;/P&gt;&lt;P&gt;Firewall is running PAN-OS 9.0.5.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you have to do anything else to export it successfully?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 11:39:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/322654#M82512</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2020-04-14T11:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/374583#M89073</link>
      <description>&lt;P&gt;'vsys1' is supposed to show up as an option.&lt;/P&gt;&lt;P&gt;Did you try to type in `vsys1` manually to see if it lets you?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 21:18:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/374583#M89073</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2020-12-15T21:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/374584#M89074</link>
      <description>&lt;P&gt;Just fyi, I have this working in an Azure environment, with a private IP on the virtual firewall in Azure, and didn't run into this problem... SAML works fine to Azure.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 21:21:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/374584#M89074</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2020-12-15T21:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/376749#M89325</link>
      <description>&lt;P&gt;What firewall you running? can you share your configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Sahir&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 15:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/376749#M89325</guid>
      <dc:creator>Sahir_Algharibih</dc:creator>
      <dc:date>2020-12-30T15:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/509567#M106082</link>
      <description>&lt;P&gt;I have the same problem, can anybody share your solution for fixed it?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 06:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/509567#M106082</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2022-07-22T06:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/562932#M114021</link>
      <description>&lt;P&gt;I'm on a much newer PanOS version, yet I have a very similar problem.&lt;BR /&gt;&lt;BR /&gt;Platform: PA-5400 with PanOS 10.2.5&lt;BR /&gt;&lt;BR /&gt;I've followed this guide:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-saml-authentication" target="_self"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/authentication/configure-saml-authentication&lt;/A&gt;&lt;BR /&gt;All certificates are installed and valid (no self-signed), I managed to complete every step, but I'm stuck at Step 5, item 4. I'm supposed to download the SAML metadata to bring it to my IdP, but I can't. Whether I turn on IdP validation and request signing or I turn them off, I get nothing in the box where I should select which service I want to turn SAML on for:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-24 alle 14.56.38.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54645i552A1EB3622BD0FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-10-24 alle 14.56.38.png" alt="Screenshot 2023-10-24 alle 14.56.38.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; Any clue on what I am missing? Is there any requirement for the request signing certificate? (e.g. it does it have to match the FQDN of the IP of the service route sending SAML requests? And which one is the service route sending them?)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:59:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/562932#M114021</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2023-10-24T12:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/562945#M114022</link>
      <description>&lt;P&gt;I have configured GP with SAML with both Azure and Duo. I have never done step 5 and IMHO, it's not needed. On Azure, I go to Enterprise Applications, go to "Palo Alto Networks - GlobalProtect" then "set up single sign on" and put in the info:&lt;/P&gt;
&lt;P&gt;Basic SAML Configuration Identifier (Entity ID)&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;A href="https://vpn.mycompany.com:443/SAML20/SP" target="_blank"&gt;https://vpn.mycompany.com:443/SAML20/SP&lt;/A&gt;&lt;BR /&gt;Reply URL (Assertion Consumer Service URL)&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;A href="https://vpn.mycompany.com:443/SAML20/SP/ACS" target="_blank"&gt;https://vpn.mycompany.com:443/SAML20/SP/ACS&lt;/A&gt;&lt;BR /&gt;Sign on URL&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;A href="https://vpn.mycompany.com" target="_blank"&gt;https://vpn.mycompany.com&lt;/A&gt;&lt;BR /&gt;Relay State (Optional)&lt;BR /&gt;Logout Url (Optional)&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 14:03:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/562945#M114022</guid>
      <dc:creator>ksalustro</dc:creator>
      <dc:date>2023-10-24T14:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SAML Metadata</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/563063#M114054</link>
      <description>&lt;P&gt;Sorry, I apparently posted in the wrong thread, after opening a dozen from Live Community: I am NOT using Azure.&lt;BR /&gt;&lt;BR /&gt;My SAML IdP is internal, and our system require a two-way trust between IdP (the SAML SSO portal) and Sp (the firewall). Nonetheless, even disabling the related configuration on the firewall, I can't export the metadata for the IdP.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 06:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-saml-metadata/m-p/563063#M114054</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2023-10-25T06:21:59Z</dc:date>
    </item>
  </channel>
</rss>

