cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

OpenConnect client with a Global Protect plugin

L4 Transporter

Hello,

 

We found that only 1 factor authentication is required when connecting to the VPN using OpenConnect client with a Global Protect plugin, it appears that it bypasses the portal authentication and only requires the gateway authentication. We have X-Auth disabled, and cannot restrict connections by Linux OS. 

 
Currently our portal is configured to authenticate with our RADIUS server, and then the gateway will authenticate using LDAP with our AD server.
 
The problem is using OpenConnect with the GP plugin (https://github.com/dlenski/openconnect) allows users to connect directly to the gateway, thus only requiring AD to authenticate.
 
It doesn't appear we can use both RADIUS and AD authentication on the gateway, so it seems we need to force users to go through the portal first, but I've searched the PAN documentation online and have had trouble finding anything relevant/useful.
 
Can someone please guide us/provide some articles regarding this?
 
Thanks in advance.
Who Me Too'd this topic