Can a Client Device Use MFA Server Profile to Authenticate into Global Protect?
12486
Created On 04/06/20 18:01 PM - Last Modified 07/30/20 19:30 PM
Question
Can a Client Device Use MFA Server Profile to Authenticate into Global Protect?
Environment
- GlobalProtect Client, GlobalProtect Portal and GlobalProtect Gateway
- PanOS version: All
- PanGP version: All
Answer
No. The Multi Factor Authentication Server Profile is used for Authentication Policy to authenticate Captive Portal Client, not GlobalProtect client.
Additional Information
The MFA methods can also be done with one of the following options:
- MFA through RADIUS Server
- Enable Two-Factor Authentication Using Certificate and Authentication Profile Enable Two-Factor Authentication Using Certificate and Authentication Profiles