DUO MFA for Clientless VPN

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L2 Linker

DUO MFA for Clientless VPN

Hi. Did anyone know if it is possible to use MFA (for examlpe with DUO) for Global Protect Clientless VPN?

 

Best regards, Markus

Highlighted
Cyber Elite

Hello,

Yes it is possible, You just need to setup the authentication method, Device ->Server Profiles,  first then add it to your VPN config.

 

Hope that helps.

Highlighted
L2 Linker

Hi. I already tried that, but I got the response bad username or password only one or two seconds after I entered my credentials. In the authentication log I can see that both authentications work well.

 

Best regards, Markus

Highlighted
Cyber Elite

Hello,

In the past I have created two Server profiles for the ones I wanted to use and then used one for the gateway and the other for the portal authentication. I have yet to play with the v8.0.x feature of MultiFactor Authentication to see how that works.

 

https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/authentica...

 

Cheers!

Highlighted
L0 Member

Hi all,

 

Same here, I experience the same issue as Markus. I try to use 2FA with DUO on Clientless GP. I get a DUO Push Notification to my phone, but in the flash of a second, the GP Portal website directly goes to Wrong password.

 

I am using 8.1.0 PAN-OS

 

If you find out something, lets share!

 

Cheers,

Sebastian

Highlighted
L2 Linker

I've also tried this and had the same result; Duo notification followed by GP invalid password message. From my discussions with Palo, it would seem that native Duo 2FA isn't supported yet for GP.

 

You can work around it in a way though by utilising an external radius server to perform the 2FA part of the authentication, rather than the native method.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!