<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Portals, or two authentication profiles or better idea to test 2FA with global protect. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387878#M90440</link>
    <description>&lt;P&gt;yes&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 19:54:15 GMT</pubDate>
    <dc:creator>mattscratt</dc:creator>
    <dc:date>2021-02-25T19:54:15Z</dc:date>
    <item>
      <title>Two Portals, or two authentication profiles or better idea to test 2FA with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387822#M90428</link>
      <description>&lt;P&gt;Howdy all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Relatively new to PA and GP, spent more time with Fortigate and Cisco at previous jobs. Work at a small company and until the pandemic and snowpoclypse VPN access was only given to select people, we all just came to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been tasked with getting Duo Security two factor authentication set up for vpn users. Problem is we cant just roll it out to all users at one time and we want time to test it with IT staff and then others. It was suggested I set up another gateway and portal. For example, we use vpn.amce.com, I should set up 2favpn.acme.com, then we can test at that address, work out the kinks etc, then replicate the settings to the production gateway/portal after training the uses.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read plenty of links in the live community about people trying similar things but nothing quite the same. As I read more and more, I'm wondering if that will actually work. I would need to assign a second IP to the ETH 1/1 interface, and would that cause havoc, need a firewall reboot etc. It just sounds like a mess in the making.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would a better way be to set up an authentication profile that uses the 2FA mechanism and sync an AD group for users? Im struggling with this, facing a deadline and would appreciate your thoughts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've contacted support, and have been told they are more break fix, not implementation and to contact our rep for implementation services engagement. I've reached out numerous ways, but have not heard back yet. Help! And thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 18:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387822#M90428</guid>
      <dc:creator>mattscratt</dc:creator>
      <dc:date>2021-02-25T18:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Two Portals, or two authentication profiles or better idea to test 2FA with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387849#M90435</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171578"&gt;@mattscratt&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;i can feel your dilemma but you do have a few options as you are already aware...&lt;/P&gt;&lt;P&gt;it will depend on other factors as all options will eventually work but its more to do with what &amp;nbsp;suits you and your org.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have a wildcard certificate, do you manage your own DNS, do you allow users to change portal address, how tekkie are your users... and on and on....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for me... &amp;nbsp; create a new portal on a secondary address, no restart required. &amp;nbsp;Keep the existing gateways but allow cookie auth to them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will keep one completely separate from the other, no AD group stuff, keep it simple...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the portal can be resolved by DNS or editing host file.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is how we currently test new rollouts but we have wildcard certs, self DNS management, a stack of available addresses and 16 gateways to choose from.... &amp;nbsp;i go for this cos any balls up only affects the user group and not our other 6k plus user base.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:13:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387849#M90435</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-25T19:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Two Portals, or two authentication profiles or better idea to test 2FA with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387858#M90436</link>
      <description>&lt;P&gt;Interesting ideas, we do manage our DNS so that helps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I assign two external IPs to the Eth 1/1 interface like in this post? Does it take a reboot?&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/multiple-addresses-in-the-same-ethernet-interface/m-p/66635#M39262" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/multiple-addresses-in-the-same-ethernet-interface/m-p/66635#M39262&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:25:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387858#M90436</guid>
      <dc:creator>mattscratt</dc:creator>
      <dc:date>2021-02-25T19:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Two Portals, or two authentication profiles or better idea to test 2FA with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387870#M90439</link>
      <description>&lt;P&gt;Are the addresses within a range with the same subnet mask.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387870#M90439</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-25T19:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Two Portals, or two authentication profiles or better idea to test 2FA with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387878#M90440</link>
      <description>&lt;P&gt;yes&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 19:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-portals-or-two-authentication-profiles-or-better-idea-to/m-p/387878#M90440</guid>
      <dc:creator>mattscratt</dc:creator>
      <dc:date>2021-02-25T19:54:15Z</dc:date>
    </item>
  </channel>
</rss>

