Vpn access using GlobalProtect with AUTENTICATION TWO-FACTOR

Reply
Highlighted
L1 Bithead

Vpn access using GlobalProtect with AUTENTICATION TWO-FACTOR

We have

The company want  that all people accessing from GLOBAL PROTECT vpn CLIENT use the two-factor autentication. We have released an U2F USB security usb key for the email. 

Does PaloAltoNetork support an external Two-Factor Autentication for the VPN? If no there are plan to develop it?

 

For us is very important the VPN GLOBAL PROTECT client can have a two-factor autentication to avoid user password theft.

 

Waiting for news.

Best Regards

Claudio Verniani

 

 

Highlighted
Cyber Elite

Re: Vpn access using GlobalProtect with AUTENTICATION TWO-FACTOR

@cverniani,

GlobalProtect supports two-factor authentication, but to really detail how you would get it to function we would need to know what system you are actually using. Things get slightly more complicated and less user friendly depending on the multi-factor system. 

Highlighted
L1 Bithead

Re: Vpn access using GlobalProtect with AUTENTICATION TWO-FACTOR

Thanks a lot for your Reply. I have two PA-820 in Ha mode, with this configuration /license.


Model PA-820
Serial # XXXXXXX
Software Version 9.0.3
GlobalProtect Agent 4.1.12
Application Version 8172-5560 (07/17/19)
Threat Version 8172-5560 (07/17/19)
Antivirus Version 3041-3551 (07/16/19)
WildFire Version 367018-369729 (07/17/19)
URL Filtering Version 20190717.20094
GlobalProtect Clientless VPN Version 0
Time Wed Jul 17 08:12:10 2019
Uptime

0 days, 16:26:23

Software Version 9.0.3

 

This is the Global Protect Portal Configuration

 

 

  2019-07-17_08h10_09.png

I can change the autentication policy. I an enable the easyest autentication (2 factor) that works with PaloAlto.

@BPry an you kindly indicate me some documentation?

Best Regards

Claudio Verniani

 

 

Highlighted
L4 Transporter

Re: Vpn access using GlobalProtect with AUTENTICATION TWO-FACTOR

@cverniani: Please provide the name of the solution, you are using.

For example RSA USB tokens are natively supported (see here https://www.paloaltonetworks.com/partners/alliance or search for your solution)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!