Any guides to setup Global Protect always on(user-logon) when using Radius with RSA ?

Reply
Highlighted
L1 Bithead

Any guides to setup Global Protect always on(user-logon) when using Radius with RSA ?

We are using a mixed 7.0.x environment for PAN-OS  and are using GP v. 3.0.2 and I want to test out using the always-on(user-logon)  or (pre-logon)  feature with Global Protect so that when our users take their laptops home, they must sign into global protect before doing anything else.  We are using RSA for authentication and I was not able to find any guides online for this.  Does anyone have any resources for this or any tips on getting this setup?  Any help would be greatly appreciated.

 

 

Thanks!

L5 Sessionator

Re: Any guides to setup Global Protect always on(user-logon) when using Radius with RSA ?

Hi,

 

First, if you want to use Always-on, mean you expect that your GP is up before opening session.... mean certificate authentication :-)

 

link: https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/set-up-the-global...

 

or you can setup SSO for GP. Mean transparent authent for GP. Using Windows authentication.

 

In you prefer to use your RSA token, it mean you prefer the on_demand config.

 

hope help.

 

V.

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!