Can Use Okta SAML for GP- "Prelogon Then On-Demand" connection method

Reply
L3 Networker

Can Use Okta SAML for GP- "Prelogon Then On-Demand" connection method

Hi Team,

 

We tried to implement the OKTA SAML authentication method for GP in our organization.

 

Does Global Protect - "Prelogon Then On-Demand" connection method supports Okta SAML for authentication (MFA).?

 

If not what is a recommended GP connection method to use Okta SAML authentication.

 

Could you please help us here! I tried all resources I didn't got an answer..!!

 

_

Regards,

Sethupathi M

 

 

Highlighted
Cyber Elite

Hi @Sethupathi 

 

Having GP authentication working with the different connection methods strongly depends on the GP agent version you are using. With which version do you try this configuration and also which PAN-OS version do you have installed on the firewall?

Btw. I assume you already know about this critical vulnerability: https://security.paloaltonetworks.com/CVE-2020-2021

So make sure you use either one of the PAN-OS versions that are fixed or enable the option "Validate Identity Provider Certificate".

 

Regards,

Remo

Highlighted
Cyber Elite

 

@Sethupathi 

 

We have configured GP Pre log on Machine cert based Authentication and then we added Authentication Profile using SAML in Azure.

To config OKTA for SAML please follow this link'

https://saml-doc.okta.com/SAML_Docs/How-to-Configure-SAML-2.0-for-Palo-Alto-Networks-GlobalProtect.h...

 

Regards

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!