How to configure two-factor auth in GlobalProtect

L4 Transporter

Hi Jeff,

You are right, it won't work.

You definitely need to have two ip-address for the gateways.

How about adding secondary ip on the interface and assigning second gateway profile to the secondary ip-address.


Portal ip-    eth 1/3

                 eth 1/3 ( GW1)

                       (secondary ip)   (GW2)

One gateway :-  uses LDAP ,  tunnel.1

Another gateway :- uses Radius, tunnel.2

Should work. But will require gateway license.



View solution in original post

L4 Transporter

Hi Parth,

I had the same idea in mind however, I can't put a secondary IP on the interface because I only have one Public IP address for that interface.  But, I see that would potentially work.

Thx for all of your help!

L3 Networker

Hi Ppatel,

I have for GP-portal ldap with attribute mail. In Radius RSA usernames are mail addres. But doen't work, when I captured radius packets comming from PA I saw the username mail addres is changed to\user.

So summary:



pwd: AD password


username send to RSA:\user1

pwd: OTP.

But I get an error from RSA because he's waiting for

Can this issue be solved? RSA users are only known by mail addres.



L4 Transporter


How about swapping the authentication profile for the Portal and the Gateway - RADIUS authentication on Portal and LDAP on the Gateway. RADIUS will push the to the gateway and then prompt. Not the typical configuration but will still do two factor authentication.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!