2 factor authentication and radius on global protect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

2 factor authentication and radius on global protect

L4 Transporter

I see where you can do radius authentication on the global protect client, does that mean you can also do 2 factor authentication?

9 REPLIES 9

L7 Applicator

Yes 😉

@Remo

Is that done on the portal under the authentication?

It depends on your needs: under authentication of the portal and/or the gateway

@Remo

So could you put radius on the portal and LDAP on the gateway

Yes, this is possible. Now I don't knlw enough about what you plan to do, but this sounds like you should also configure the same radius profile on the gateway and use authentication cookies to force the users not too much to login.

Hello,

What I did in the past previous to 7 or 8, wsa the setup a different authentication method for the portal and gateway. This way one would prompt for the external OTP and then the users would get prompted for their network creds. I never tried it with an authentication sequence but it might work that way as well?

 

Regards,

@OtakarKlier

 

So what was your portal set to use? what was your gateway set to use?  I think you are doing what I am trying to do. I am trying to replace a VPN that use Radius, OTP and LDAP to access a segregated part of our network using a ASA 5510 FW

Hello @jdprovine,

I set the portal to use the external OTP and the gateway to use RADIUS(active directory creds. Sounds like you would like 3 options?)

 

https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentica...

 

If using 3 options, then maybe look at:

 

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/aut...

 

Just thinking out loud.

 

Cheers!

@OtakarKlier

I will check out your links, not sure I want to user 3 methods I just know that it was set up for the VPN I am trying to replace, not sure why it was set up that way or if I can do the same thing on the PA

  • 2441 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!