I am assuming that you are wanting to use this for SSL VPN ?
I know the PA devices support 2-factor authentication as there are guides for Nordic Edge, I would presume that it would be the same process for any other 2-factor auth process.
See the following link for the nordic edge solution http://www.nordicedge.se/palo-alto
NordicEdge is a great solution and you don't have to care about OTP page, it's automatic due the RADIUS response.
Nice integration with Palo Alto (and all other major vendors to tell the truth), in one hour you can have domain user logging into SSL VPN with strong authentication. OTP can be sent via sms, email o smartphone app,
A demo 30-days with SMS support is available to try, I suggest the product.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!