I see where you can do radius authentication on the global protect client, does that mean you can also do 2 factor authentication?
Yes, this is possible. Now I don't knlw enough about what you plan to do, but this sounds like you should also configure the same radius profile on the gateway and use authentication cookies to force the users not too much to login.
What I did in the past previous to 7 or 8, wsa the setup a different authentication method for the portal and gateway. This way one would prompt for the external OTP and then the users would get prompted for their network creds. I never tried it with an authentication sequence but it might work that way as well?
So what was your portal set to use? what was your gateway set to use? I think you are doing what I am trying to do. I am trying to replace a VPN that use Radius, OTP and LDAP to access a segregated part of our network using a ASA 5510 FW
I set the portal to use the external OTP and the gateway to use RADIUS(active directory creds. Sounds like you would like 3 options?)
If using 3 options, then maybe look at:
Just thinking out loud.
I will check out your links, not sure I want to user 3 methods I just know that it was set up for the VPN I am trying to replace, not sure why it was set up that way or if I can do the same thing on the PA
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!