GP+DECRYPT+MFA

Reply
Highlighted
L1 Bithead

GP+DECRYPT+MFA

 

Hello,

 

I have been playing around with this setup:

 

- user connect to internal network with globalprotect

- initiating any connection to internal resources trigger ether a redirect to captive portal for MFA challenge or a global protect popup with the captive portal URL for MFA challenge.

 

This seem to work as expected, but I have encounter a show-stopping problem:

 

Accessing the palo-alot mgmt URL i expected to be redirected to the captive portal page for multi-factor-auth. but instead I got access to the URL. Investigating I noticed that the decryption failed (for some reason for this to work you have to decrypt SSL. Initiating an SSH connection will trigger the MFA popup from GP but you do not need to decrypt ... that in itself is a bit strange).

 

Anyhow I suspect that there are some chiper issue that fail when PA tries to decrypt the default SSL certificates. I could off curse solve this by replacing the management SSL certificates but this means that any SSL internal resource that fail the decryption will be accessible without MFA.

 

Should not the default action here be to drop the connection? As far as I am aware there is no possible security policy to deny access if decryption fail.

Highlighted
L7 Applicator

Re: GP+DECRYPT+MFA

Is the mgmt profile configured on the same interface that hosts the CaptivePortal page? 

setting the profile on a 'remote' interface (connection needs to travel through the firewall to get to the interface) may resolve your issue

reaper - PANgurus.com
I drink and I know things
Highlighted
L1 Bithead

Re: GP+DECRYPT+MFA

Hello,

 

Thanks for the reply.

 

No its not. The captive protal is hosted on the tunnel interface used by globalprotect. Works as a charm on all other stuff except the mgmt interface. I think I will replace the build in certificates and see what happens. Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!