- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-24-2018 03:45 AM - edited 04-24-2018 03:59 AM
Global Protect VPN Solution is defined with Pre-login and always-on VPN features.
Workflow:
Required: MFA integration With Pre-login
My main scope is to add more strong authentication mechanism, as with pre-logon,
Step1: machine are authentication and authorized once it boots up baed on First Authentication factor (Client-Certificate) to access AD servers.
Step2: adding to that Second factor Authentication Factor Credential logins to be able to open the laptop itself.
In case of Client-Certificate is compromised then attacker can import it to its machine and do step1 then step2 (as device credentials is already know to attacker - already his machine-).
Proposal A:
So with My proposal A , attacker can still connected through VPN. maybe he doesn`t have access to internal resources without Valid OTP but he stills can do DOS attack to bring down my service.
So hope it is a good challenge for you to think about 🙂 ....