RA VPN - SAML testing without affecting production

cancel
Showing results for 
Search instead for 
Did you mean: 

RA VPN - SAML testing without affecting production

L1 Bithead

Is there a way to test SAML authentication for Remote Access without affecting the production environment? In FortiGate I can create multiple independent portals and assign specific users/groups to the portals, but not sure if it is possible in PA. I am a bit concerned about having to ask for long maintenance windows in order to making SAML authentication works, and would be great if there would be an option to test this without bothering the users. Thanks.

1 ACCEPTED SOLUTION

Accepted Solutions

Cyber Elite
Cyber Elite

@moragusa27,

You can build it out by just using loopback interfaces, you don't need to utilize the actual interface address to built these out. 

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

@moragusa27,

You can create multiple GlobalProtect Portal/Gateway configurations without any issue and just assign it the new Authentication Profile. 

@BPry,

Yes, I have tried that but it looks like these Portas/Gateways cannot be working at the same time. I mean, I cannot specify the same Outside interface and same IP adress for the new Gateway/Portals.

 

Is it possible to have multiple Portals/Gateways enabled at the same time on the same interface/IP? Or should I decide to enable onle one? Thanks.

Cyber Elite
Cyber Elite

@moragusa27,

You can build it out by just using loopback interfaces, you don't need to utilize the actual interface address to built these out. 

Thanks, it has worked fine for me. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!