I have configured Azure SAML SSO for GlobalProtect. When I try to export Metadata from PaloAlto FW for global-protect service, there is a mandatory section to select which virtual system. But in my case, there is no virtual system to select from. I am not sure what's the issue. Any idea what's going on?
Thanks for your help in advance!
I did delete and created the profile several times, still same issue. I think SAML is not working for me, because of the way our Azure environment setup, where the firewall is pulling a private IP address from Azure DHCP & that is being Natted by Azure, where we have no control over it.
Was your setup in Azure too? if so, can you please provide the steps you used to get it work?
Yes, the issue is the way Azure environment is built. From experience, you can't get SAML running because your Azure FW is using a private IP address from a DHCP server, and that private IP get's natt'ed by Azure on your behalf. All that, causes it to break. I've tested the same SAML configuration on a local firewall, and it worked first time. Therefore, Azure is no longer an option for our GP solution.
I hope that helps!
I'm currently experiencing this on an on-premise PA-220 firewall. When you want to export the Metadata file from the firewall, the authentication profile is there already. However, clicking the VSYS drop-down gives no value and so the 'OK' button is greyed out.
Firewall is running PAN-OS 9.0.5.
Did you have to do anything else to export it successfully?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!