GP external gateway - Connection method Pre logon Always on

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

GP external gateway - Connection method Pre logon Always on

Cyber Elite
Cyber Elite

We are using SAML in Azure for GP external gateway connection.

When connection method is on demand we get mobile push notification and user gets connected to the GP.

 

Testing with Connection method Pre logon Always on, i am not getting mobile push notification.

Need to confirm is this by design?

 

or is there any config i can do so that Connection method Pre logon Always on  gives me mobile push notification?

 

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

TAC confirmed with Engineering team this is not possible.

MP

Help the community: Like helpful comments and mark solutions.

View solution in original post

9 REPLIES 9

Community Team Member

Hi @MP18 ,

 

Not sure if this is by design. 

I'd recommend reaching out to TAC and have them confirm with engineering if it's by design or not.

 

Cheers !

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

As per TAC this is by design but i asked him to confirm with Engineering also.

MP

Help the community: Like helpful comments and mark solutions.

TAC confirmed with Engineering team this is not possible.

MP

Help the community: Like helpful comments and mark solutions.

L7 Applicator

Hi @MP18 

I don't really get it. Why isn't this possible exactly? With SAML you get single sign on, but as you have another loginfactor the push notification should be sent - so why not in your configuration? Don't give up too easily with answers from TAC 😉

 

If there really isn't a way without a feature request where you have to wait, what about using RADIUS MFA connectior for your always-on clients? Does it maybe work this way with SSO and push notifications?

We have Global protect PRe log on  Always on for pilot testing.

We have SAML configured where we get the push notifications on mobile for authentication.

 

We are using Azure SAML.

When user put the domain password during log on then GP client connects automatically they do not get mobile push notifications.

Opened ticket with TAC almost 2 weeks ago and today he confirmed that this is expected behaviour.

We can not force push mobile notifications while using pre log on always on connection method.

 

Also as our current setup we only want to use SAML using Azure.

 

 

MP

Help the community: Like helpful comments and mark solutions.

L7 Applicator

You are using the newest GP version? Or at least something above 5.0.2?

(I am asking as I intended to do a similar setup ... but this now does not sound very good ...)

I am using GP client 5.0.4.16

MP

Help the community: Like helpful comments and mark solutions.

L7 Applicator

But the push notification is sent by your SAML IdP or the attached MFA service right? And GP officially supports "Pre-logon followed by SAML". So when viewing from the other side: why is this an issue of GP as the IdP is sending or at least triggering the push notification?

 

We do not have MFA configured.

As per PA while using Global protect External  and using SAML you can not have MFA.

 

I could not find answer for this checked with PA and also with our SE.

Only option is to use on demand connection method.

As per PA we can submit the feature request to them.

 

 

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 4720 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!