GlobalProtect multiple authentication profiles? External contractors, ldap users with certs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect multiple authentication profiles? External contractors, ldap users with certs

L0 Member

Hi 🙂

Im looking for solution. I need to configure global protect to:

  • Login LDAP users. For ldap users it has to check if client has machine certificate on it
  • Login external contractors. They have accounts created on palo device and there is no need to check for certificate

And im stuck to be honest. Im coming from cisco networking where i can create multiple profiles with separate configurations.

Is it possible to create it on palo with only one GPPortal and one GPGateway?

I configured authentication tab like below and it successfully login ldap users and check for certificate but it dont work for local users. I understand that is because those 2 client authentication methods dont work as i though and i need authentication sequence.

typovy_0-1719334094268.png

So i made a sequence but now if i set "Allow authentication with user credentials or client certificate" to no (because i want to check ldap user cert) local users cant log in because they dont have cert. I feel little bamboozled 😕

typovy_1-1719334313928.png

 

 

2 REPLIES 2

Cyber Elite
Cyber Elite

@typovy,

Any reason why you're trying to limit yourself to one portal and one gateway? Personally I would recommend having contractors completely separate from your normal users. I isolate them to their own zone completely with a dedicated portal and gateway to utilize going forward. It makes it so I don't have to worry about a misconfiguration granting access to contractors when it shouldn't, and then you don't need to worry about competing authentication settings at all.

We have only one public IP address and we didn't want to overcomplicate it too much with loopback interfaces.

  • 221 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!