Conditional rules for GP MFA auth?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Conditional rules for GP MFA auth?

L4 Transporter

Is it possible to apply conditional rules on a GlobalProtect login so the means of login can vary? For example; If a Windows client is operating within a particular country or public IP range, just require simple SAML user login and maybe AD machine membership. However, if the client is outside of the country/ip-range, prompt the user for an MFA login.

1 REPLY 1

Cyber Elite
Cyber Elite

Hi @JimMcGrady ,

 

That is a very interesting question!  The only option you have for different authentication policies on the portal or gateway is OS.  That doesn't help.

 

However, you can have clients select different gateways based upon countries, and the gateways can be configured with different authentication methods.

 

For example, you could have SAML for your portal login.  The login info is cached by the portal and sent to the gateway.  One gateway can have the same SAML, and the client will not be prompted for login again.  Another gateway could have the same SAML (so same creds) with MFA enabled, and those clients will be prompted for MFA.

 

MFA is always recommended for RA VPN.  Another option you may consider is have a long cookie lifetime for the trusted country and a short lifetime for the untrusted countries.  As long as the cookie is not expired, users will not be prompted for MFA.  However, they will not be prompted for username and password either.  This is not the portal/gateway authentication cookie, but rather the IdP MFA authentication cookie.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 891 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!