Can Use Okta SAML for GP- "Prelogon Then On-Demand" connection method

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Can Use Okta SAML for GP- "Prelogon Then On-Demand" connection method

L3 Networker

Hi Team,

 

We tried to implement the OKTA SAML authentication method for GP in our organization.

 

Does Global Protect - "Prelogon Then On-Demand" connection method supports Okta SAML for authentication (MFA).?

 

If not what is a recommended GP connection method to use Okta SAML authentication.

 

Could you please help us here! I tried all resources I didn't got an answer..!!

 

_

Regards,

Sethupathi M

 

 

2 REPLIES 2

L7 Applicator

Hi @Sethupathi 

 

Having GP authentication working with the different connection methods strongly depends on the GP agent version you are using. With which version do you try this configuration and also which PAN-OS version do you have installed on the firewall?

Btw. I assume you already know about this critical vulnerability: https://security.paloaltonetworks.com/CVE-2020-2021

So make sure you use either one of the PAN-OS versions that are fixed or enable the option "Validate Identity Provider Certificate".

 

Regards,

Remo

Cyber Elite
Cyber Elite

 

@Sethupathi 

 

We have configured GP Pre log on Machine cert based Authentication and then we added Authentication Profile using SAML in Azure.

To config OKTA for SAML please follow this link'

https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.h...

 

Regards

MP

Help the community: Like helpful comments and mark solutions.
  • 2613 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!