Global Protect Integration with Azure SAML w/ Multiple Gateways

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect Integration with Azure SAML w/ Multiple Gateways

L1 Bithead

I'm trying to setup an integration with 2 firewalls at different locations.  The portal and 1 gateway reside on 1 of the firewalls, and i've used this:

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008U48CAE

 

to get that going successfully.  The 2nd firewall, which has a certificate w/ a different FQDN, doesn't allow users to connect.  My thinking was I needed to create a 2nd enterprise application using the 2nd FQDN or is that not necessarily?

3 REPLIES 3

L0 Member

Yeah sounds like the second enterprise application is exactly what you need since you are going to have a different SAML configuration for the other FQDN

Cyber Elite
Cyber Elite

Hello,

 

What error are you getting when users are trying to connect? You are able to use the same SAML Azure App for multiple GlobalProtect gateways, you just need to add the additional gateways under the Basic SAML configuration urls settings in the Azure app. And have the SAML metadata imported on the gateway firewall. 

L3 Networker

Like Claw is saying you just need to add your additonal gateways in your Azure Entra Global Protec single sign on settings.

 
  • 943 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!