On demand GP MFA with manage engine identity 360 and NPS server

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

On demand GP MFA with manage engine identity 360 and NPS server

L1 Bithead

The current setup for User VPN Connection requires users to log in using their email address as the username and OTP from google authenticator as the password.

For VPN Client Verification, we would like to update the configuration to include password-based authentication for each user.

  • Example: User logs in with their email address (username) and password.
  • After successful authentication, the user is then prompted to enter the OTP code received via the authenticator app
  • User is created on identity 360 and its client upload on NPS sever and radius server and authentication profile is configured on GP.
  • How I achieve Username + password + OTP
  • currently Username + OTP only
1 REPLY 1

Community Team Member

Hi @K.Mishra548222 ,

 

Currently, users log in to GlobalProtect using username + OTP, and you’d like to move to username + password, followed by OTP.

 

To achieve this, you’ll need to add password validation on the NPS server before the OTP challenge. The NPS server will handle both the username/password verification and the OTP challenge, while the Palo Alto firewall simply points to the NPS server via the server profiles you create and attach to the GP portal/gw, and forwards the authentication requests.

 

Make sure your NPS server or RADIUS plugin supports multi-factor (password + OTP) authentication, such as the Google Authenticator RADIUS plugin or a similar MFA extension.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 167 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!