2 factor authentication and radius on global protect

L4 Transporter

2 factor authentication and radius on global protect

I see where you can do radius authentication on the global protect client, does that mean you can also do 2 factor authentication?

L7 Applicator

Re: 2 factor authentication and radius on global protect

Yes ;)

L4 Transporter

Re: 2 factor authentication and radius on global protect

@vsys_remo

Is that done on the portal under the authentication?

L7 Applicator

Re: 2 factor authentication and radius on global protect

It depends on your needs: under authentication of the portal and/or the gateway

L4 Transporter

Re: 2 factor authentication and radius on global protect

@vsys_remo

So could you put radius on the portal and LDAP on the gateway

L7 Applicator

Re: 2 factor authentication and radius on global protect

Yes, this is possible. Now I don't knlw enough about what you plan to do, but this sounds like you should also configure the same radius profile on the gateway and use authentication cookies to force the users not too much to login.

L7 Applicator

Re: 2 factor authentication and radius on global protect

Hello,

What I did in the past previous to 7 or 8, wsa the setup a different authentication method for the portal and gateway. This way one would prompt for the external OTP and then the users would get prompted for their network creds. I never tried it with an authentication sequence but it might work that way as well?

 

Regards,

L4 Transporter

Re: 2 factor authentication and radius on global protect

@Otakar.Klier

 

So what was your portal set to use? what was your gateway set to use?  I think you are doing what I am trying to do. I am trying to replace a VPN that use Radius, OTP and LDAP to access a segregated part of our network using a ASA 5510 FW

L7 Applicator

Re: 2 factor authentication and radius on global protect

Hello @jdprovine,

I set the portal to use the external OTP and the gateway to use RADIUS(active directory creds. Sounds like you would like 3 options?)

 

https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentica...

 

If using 3 options, then maybe look at:

 

https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/aut...

 

Just thinking out loud.

 

Cheers!

L4 Transporter

Re: 2 factor authentication and radius on global protect

@Otakar.Klier

I will check out your links, not sure I want to user 3 methods I just know that it was set up for the VPN I am trying to replace, not sure why it was set up that way or if I can do the same thing on the PA

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!