Palo Alto Admin Login MFA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto Admin Login MFA

L3 Networker

Can the palo alto admin login page be configured for MFA using something like Okta or DUO?

5 REPLIES 5

Cyber Elite
Cyber Elite

I only see SAML as potentially being supported (as an auth profile) but not MFA.

 

 

Help the community: Like helpful comments and mark solutions

Community Team Member

Hi @Stevenjwilliams83 ,

 

Unless I misunderstood your question I would try this.  Have an authentication profile using MFA in your Authentication settings:

 

MFAMFA

 

 

MFAMFA

 

 

Hope this helps,

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

everything I have been reading seems to elaborate the use MFA DUO for global protect. 

@Stevenjwilliams83 MFA in authenticaion profile is only supported for Captive Portal/Authentication policies. The admin authenticaion can support 2FA by using RADIUS or TACACS server or as you mentioned SAML. Please see the official compatibility matrix below: 

 

https://docs.paloaltonetworks.com/compatibility-matrix/mfa-vendor-support/mfa-vendor-support-table.h...

 

L3 Networker

@Stevenjwilliams83 You can do this, but if you have a pair of Palo's (and you most likely do), you'll run into the same issue that I had and that is the syncing of the Authentication settings with the peer.  Because you can only have one Authentication Profile in the Authentications Settings and you can't tell it not to sync with the peer, whatever Profile you've set up will probably have the IP of your Palo - which is different from its peer.  Thus, when you try to log into the peer with your new MFA method, you'll get redirected to your other Palo and it will fail.  So yes, it does work, but only for one of the pair.  If I could tell it to not sync the Authentication settings with the peer and have a separate Authentication Profile for each node, I'd be golden.  But I can't so I'm not.  haha.

 

Let me know if this doesn't make sense and I can try to go into more detail.

  • 5196 Views
  • 5 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!