- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-29-2023 01:37 AM
Hi,
We have configured GP with CISCO DUO. If i connect in a fisrt moment to GP is successfull. But if i disconnect and connect again the credentials are not being asked. Its like there is a cache that GP is saving my credentials and DFA for a momento. How can i configure that always i connect to GP the password is asked and DFA. If its possible saving the username field. Where is this configured?. thanks
11-29-2023 02:11 AM
first, go and check if you have authentication cookie enabled on the gateway Network > globalprtoect > gateways > agent > client settings > authentication override
also check if the conditional access configuration of DUO is set to. 'every time' as it may be allowing a grace period where a SAML token is accepted
11-29-2023 03:23 AM
Yes, i have enabled both options:
-Generate cooki for auth override.
-Accept cookie for auth override.
I configured 8 hours.
So that means that the credentials will be cached for 8 hours? how can i configure that always users connect GP need introduce password and DUO token?
thanks
11-29-2023 03:38 AM
no, this setting gives out a cookie thats valid for 8 hours. That cookie will be used to authenticate instead of your regular authentication mechanism for the duration you configured (8 hours)
if you disable "accept cookie for auth override" for the gateway, your users will always be prompted to authenticate via DUO
11-29-2023 04:15 AM
OK, so this config would not solve my main issue.
How can i do for user always need to add the password and token when they disconnect from GP. I did a test changing GATEWAY->AGENT-> Save credential -> save only username but the result is the same. After a succesful connection keeps the credentials and token for next time.
11-30-2023 05:32 AM
you can switch to SAML. in this case there is no notion of locally stored credentials, you get a token from the IdP that is subject to conditional access
if conditional access is set to require re-authentication every time, you get taken to the login page via a browser
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!