05-09-2019 03:55 AM
I have a customer who is trying to configure MFA in GP with RSA SecureID server with Radius server profile (Not the MFA profile that was introduced with 8.1).
The first factor should be user name and password and the second factor should be an OTP token.
Both username, passowrd and token should be validated by the RSA server.
I have done the configuration by following the below KB
Now when i try to authenticate GP shows only the first step (Password), and it does not prompt for the OTP.
So i need to know if there is a configuration on GP to enable the OTP popup?
Also if am using an email/SMS token, the firewall should send a request first in order for the token to be generated, is there is a way to configure this method in PA?
also is there is a behavior change between 8.0 and 8.1 in the way GP handles MFA with Radius server profile?
10-11-2019 01:45 PM
Have you looked at the Authentication profiles and sequencing?
Might be worth a look. Also support is always around to help out if you need a resolution quicker.
10-12-2019 06:33 AM
I've heard that Palos don't do auth sequences like you would like them to in this specific situation.....it will check for a successful authentication and when it takes, it stops.....it doesn't necessarily go through each one, every time....which is what we are looking for here i believe.
10-12-2019 06:34 AM
11-01-2019 02:59 PM
Unfortunetely I have no idea on how to configure this on RSA RADIUS side - never used this product
03-04-2021 02:04 PM
In case anyone wants to read this, I have written a blog that helps with this subject here:
DOTW: MFA and 2FA for GP and NGFW
Please check it out.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!