Yes you can do that.
but just be aware...
if the portal ever becomes unavailable the local client will use the last known portal config and attempt to connect to the gateway directly, so only passcode will be required... this may also be confusing for users as they will not know if to use password or passcode...
why do you feel you need both ?
does your sms passcode also require a username and PIN?
I have multiple gateways and that means that Firewalls that have the portals they don't have the gateways and the firewalls with the gateways they don't have any portals .
I tried to attach LDAP-AD profile that works in the portal and the profile for the SMS provider to the gateways which I have configured the firewalls to send vs source-ip only. But doesn't work because it seems that app sends the ad password as passcode since I get SMS that my account is locked but if I do the opposite and I use the SMS auth in the Portal and the LDAP-AP profile in the gateway then I get SMS , I put that since I am getting prompted and then auth fail with no reason but I suspect that this SMS passcode is being used in the gateway .
No , because user should put one time user/pass that will be checked against AD and then on the gateway I would like user to put one time password through another AD that delivers the SMS to user .
I made it work with Portal SMS and gateway AD credentials but I get 3 times to provide password and two of them is AD credentials .
I am using MFA with RSA and on Portal and Gateway I have same authen profile which is AD then on Authen policy i choose
RSA and it works fine.
Seems in out setup when user logins to PC he also gets login to GP client automatically as it is always on.
Hi Georgios. At the end it does work? I have a similar issue
I probe the integration between Palo Alto - Google Authenticator trough RADIUS and it works perfectly. But now I need to integrate the same with LDAP in the entire authentication process. So customer wants:
GP user opens and authenticate - User Mapping with LDAP Profile - Sends to user the authcode - login with the token
I can't fin the configuration process. Can you help me?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!