IOS and Globalprotect using Multifactor authenticator

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IOS and Globalprotect using Multifactor authenticator

L0 Member

We are facing a problem on IOS devices related to globalprotect using Multifactor Authenticator with Azure. We tried forming a certificate chain a root certificate and an intermediate certificate.

We added to the root certificate an extra attribute which is "IP= "IP Address" from Subject Alternative Name (SAN) field". As for the intermediate certificate we added an extra option which is "Host Name= "DNS" from Subject Alternative Name (SAN) field in the Certificate Attribute" and the value of the internal DNS server.

Then we downloaded globalprotect and installed the certificates on the IOS device, however, an error appeared which is "Connection Failed GlobalProtect failed to connect to the login server. Contact your IT help desk to resolve the issue.An SSL error has occurred and a secure connection to the server cannot be made".

We then tried to install the certificates on the IOS device however, without pressing “Always Trust” but still we were getting the same error.

Note that we tried the above certificate formats because before we didn’t use Multifactor authentication and globalprotect was not working on IOS and Android. However, when we did the above certificates, globalprotect started working on both IOS and Android. GlobalProtect  NGFW 

0 REPLIES 0
  • 715 Views
  • 0 replies
  • 1 Likes
  • 47 Subscriptions
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!