Global Protect need to ask for password all time we connect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Global Protect need to ask for password all time we connect

L4 Transporter

Hi,

 

We have configured GP with CISCO DUO. If i connect in a fisrt moment to GP is successfull. But if i disconnect and connect again the credentials are not being asked. Its like there is a cache that GP is saving my credentials and DFA for a momento. How can i configure that always i connect to GP the password is asked and DFA. If its possible saving the username field. Where is this configured?. thanks

5 REPLIES 5

Cyber Elite
Cyber Elite

first, go and check if you have authentication cookie enabled on the gateway Network > globalprtoect > gateways > agent > client settings > authentication override

 

also check if the conditional access configuration of DUO is set to. 'every time' as it may be allowing a grace period where a SAML token is accepted

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Yes, i have enabled both options:

-Generate cooki for auth override.

-Accept cookie for auth override.

I configured 8 hours.

 

So that means that the credentials will be cached for 8 hours? how can i configure that always users connect GP need introduce password and DUO token?

 

thanks

Cyber Elite
Cyber Elite

no, this setting gives out a cookie thats valid for 8 hours. That cookie will be used to authenticate instead of your regular authentication mechanism for the duration you configured (8 hours)

 

if you disable "accept cookie for auth override" for the gateway, your users will always be prompted to authenticate via DUO

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

OK, so this config would not solve my main issue.

 

How can i do for user always need to add the password and token when they disconnect from GP. I did a test changing GATEWAY->AGENT-> Save credential -> save only username but the result is the same. After a succesful connection keeps the credentials and token for next time.

 

 

Cyber Elite
Cyber Elite

you can switch to SAML. in this case there is no notion of locally stored credentials, you get a token from the IdP that is subject to conditional access

if conditional access is set to require re-authentication every time, you get taken to the login page via a browser

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1398 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!