DUO MFA for Clientless VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

DUO MFA for Clientless VPN

L2 Linker

Hi. Did anyone know if it is possible to use MFA (for examlpe with DUO) for Global Protect Clientless VPN?

 

Best regards, Markus

5 REPLIES 5

Cyber Elite
Cyber Elite

Hello,

Yes it is possible, You just need to setup the authentication method, Device ->Server Profiles,  first then add it to your VPN config.

 

Hope that helps.

L2 Linker

Hi. I already tried that, but I got the response bad username or password only one or two seconds after I entered my credentials. In the authentication log I can see that both authentications work well.

 

Best regards, Markus

Hello,

In the past I have created two Server profiles for the ones I wanted to use and then used one for the gateway and the other for the portal authentication. I have yet to play with the v8.0.x feature of MultiFactor Authentication to see how that works.

 

https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentica...

 

Cheers!

Hi all,

 

Same here, I experience the same issue as Markus. I try to use 2FA with DUO on Clientless GP. I get a DUO Push Notification to my phone, but in the flash of a second, the GP Portal website directly goes to Wrong password.

 

I am using 8.1.0 PAN-OS

 

If you find out something, lets share!

 

Cheers,

Sebastian

L2 Linker

I've also tried this and had the same result; Duo notification followed by GP invalid password message. From my discussions with Palo, it would seem that native Duo 2FA isn't supported yet for GP.

 

You can work around it in a way though by utilising an external radius server to perform the 2FA part of the authentication, rather than the native method.

  • 5487 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!