<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OKTA SAML panorama authentication? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386369#M90242</link>
    <description>&lt;P&gt;I see the redirect page, I login using my SAML u/p and then it redirects me back to the panorama login screen.&amp;nbsp; I have done all those commands and have a case open with support who were less than helpful so I figured I would ask here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;For instance I test that SAML profile from the CLI and it spits out the test URL:&amp;nbsp; https://&amp;lt;panIP&amp;gt;:443/SAML20/SP/TEST which when pasting into a browser opens up an OKTA authentication window, I login and it says 'signing into the Palo Alto Networks UI' or something along those lines and its back to the login screen.&amp;nbsp; So authentication works it just doesn't work to actually login to panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the logs I see PAN_AUTH_SUCCESS SAML response and redirects but again it just doesn't log me in.&amp;nbsp; &amp;nbsp;I would copy/paste the output but not really sure what is considered sensitive in those logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 14:09:55 GMT</pubDate>
    <dc:creator>drewdown</dc:creator>
    <dc:date>2021-02-17T14:09:55Z</dc:date>
    <item>
      <title>OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386169#M90214</link>
      <description>&lt;P&gt;Trying to get this working and I am able to authenticate using OKTA SAML&amp;nbsp; via the button on the login screen but when I do (after entering u/p on the OKTA page) it redirects me back to the Panorama login page.&amp;nbsp; I see PAN_AUTH_SCUESS SAML on the CLI but never an 'auth-sucess' in the GUI (Monitor &amp;gt; Logs ? System) because it never actually logs me in.&amp;nbsp; The only thing I see in the GUI when attempting to login via SAML is a saml_client_redirect for that SAML profile when I attempt to use it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have Admin SAML logins to panorama working and if so any idea what is going on here?&amp;nbsp; I dont use GP or captive-portal and I only want this working with admin logins.&amp;nbsp; This is the document I followed:&amp;nbsp;&lt;A href="https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-Admin-UI.html" target="_blank"&gt;https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-Admin-UI.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 16:06:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386169#M90214</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-02-16T16:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386327#M90233</link>
      <description>&lt;P&gt;SAML will work with web gui based logins, as we use it for authentication to our lab/demo equipment, as we mock up different configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I understood your comment, you see the SAML redirect (in the webpage) but does not go any further.&amp;nbsp; If you are seeing this, then SAML may not be configured correctly or there is some other message.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My recommendation for you to do, is to get into CLI and run the below commands and then follow an authentication attempt for your user:&lt;/P&gt;
&lt;P&gt;one command could be&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;test mfa-vendors mfa-server-profile &amp;lt;profile name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;another command you could run also is&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tail follow yes mp-log authd.log&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You would be looking for something like this...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1613565554926.png" style="width: 589px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29966iF562F1C81C73EC63/image-dimensions/589x308?v=v2" width="589" height="308" role="button" title="SteveCantwell_0-1613565554926.png" alt="SteveCantwell_0-1613565554926.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 12:40:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386327#M90233</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-02-17T12:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386369#M90242</link>
      <description>&lt;P&gt;I see the redirect page, I login using my SAML u/p and then it redirects me back to the panorama login screen.&amp;nbsp; I have done all those commands and have a case open with support who were less than helpful so I figured I would ask here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;For instance I test that SAML profile from the CLI and it spits out the test URL:&amp;nbsp; https://&amp;lt;panIP&amp;gt;:443/SAML20/SP/TEST which when pasting into a browser opens up an OKTA authentication window, I login and it says 'signing into the Palo Alto Networks UI' or something along those lines and its back to the login screen.&amp;nbsp; So authentication works it just doesn't work to actually login to panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the logs I see PAN_AUTH_SUCCESS SAML response and redirects but again it just doesn't log me in.&amp;nbsp; &amp;nbsp;I would copy/paste the output but not really sure what is considered sensitive in those logs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:09:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386369#M90242</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-02-17T14:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386451#M90255</link>
      <description>&lt;P&gt;Have you considered trying to use 2FA for authentication vs exlcusively SAML?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example... we use LDAP as our first factor, and then Okta as our 2nd factor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We authenticate first to the Panorama using , then put in Okta creds, with the popup window and then I can log in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1613586677639.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29976i8BDCACB7BA8A3C38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SteveCantwell_0-1613586677639.png" alt="SteveCantwell_0-1613586677639.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 18:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386451#M90255</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-02-17T18:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386600#M90279</link>
      <description>&lt;P&gt;No because I wanted to get SAML working first but DUO MFA is on the roadmap once we got SAML working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either way it shouldn't matter what number of authentication methods I choose it should still log me into the panorama.&amp;nbsp; Whether I am using, local, LDAP, OKTA, SAML is irrelevant as those are simply authentication methods.&amp;nbsp; LDAP and local works, SAML does not.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:00:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386600#M90279</guid>
      <dc:creator>drewdown</dc:creator>
      <dc:date>2021-02-18T14:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: OKTA SAML panorama authentication?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386647#M90284</link>
      <description>&lt;P&gt;Log in to the Panorama that manages Prisma Access and configure the SAML signing certificate that you want to use with SAML 2.0. ... Configure SAML Authentication for Prisma Access Using Okta With the Prisma Access App Select. Device. ... Click. Generate. ... Select the certificate, then click. ... Export the certificate in PEM format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.tellsubway.website/" target="_self"&gt;TellSubway&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 17:57:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/okta-saml-panorama-authentication/m-p/386647#M90284</guid>
      <dc:creator>Zboncak</dc:creator>
      <dc:date>2021-02-18T17:57:12Z</dc:date>
    </item>
  </channel>
</rss>

