- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-22-2020 04:16 AM
Good day!
Who know and can help:
Is scenario when it is working NGFW PA-220, LocalUser , GlobalProtect and Duo 2FA (without AD, RADIUS, LDAP etc.) for small users group (like 10 members vpn)?
I believe in that very simple way, but didn't found out information about it, and configuration example.
https://help.duo.com/s/article/4254?language=en_US
https://www.reddit.com/r/paloaltonetworks/comments/9uq5os/globalprotect_and_duo_native_mfa/
Thanks.
02-24-2020 03:22 AM - edited 02-24-2020 03:24 AM
Duo can't be used for MFA for local users of Palo Alto Global Protect. It seems to be limitation of PA devices. We tried same in the past in our environment and engineer said it's not possible. Even Duo have one article on it.
https://help.duo.com/s/article/2322?language=en_US
Duo MFA solution for Captive Portal of Palo Alto will work with a local database but i think it will not fulfill your use case.
Hope it helps!
Mayur
02-24-2020 03:22 AM - edited 02-24-2020 03:24 AM
Duo can't be used for MFA for local users of Palo Alto Global Protect. It seems to be limitation of PA devices. We tried same in the past in our environment and engineer said it's not possible. Even Duo have one article on it.
https://help.duo.com/s/article/2322?language=en_US
Duo MFA solution for Captive Portal of Palo Alto will work with a local database but i think it will not fulfill your use case.
Hope it helps!
Mayur
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!