OTP is prompted twice for GlobalProtect configured with two factor authentication

OTP is prompted twice for GlobalProtect configured with two factor authentication

6453
Created On 10/28/21 15:33 PM - Last Modified 04/28/23 21:19 PM


Symptom


  • Two factor authentication is configured for GlobalProtect (GP).
  • When the client tries to connect to GP, OTP is prompted twice.


Environment


  • Palo Alto Networks Firewall
  • Supported  PAN-OS
  • GlobalProtect (GP)
  • Multi Factor or Two Factor authentication configured for GP.


Cause


  • GlobalProtect App will pass on the Portal credentials to the gateway for seamless authentication.
  • After successful two-factor authentication (OTP) with Portal, GP will pass on the portal OTP to the Gateway.
  • Since the OTP is changed during gateway authentication, the Radius server (RSA server) will send an "Access-Reject" message.
  • Due to this Radius message, the gateway authentication fails and user is prompted to re-authenticate with the gateway.


Resolution


  1. In the portal, enable "Generate a cookie for authentication override". Do not enable "accept cookies".
  2. With this configuration, will always be prompted to authenticate when connecting to the portal.
  3. In the gateway, enable only "accept cookie" and set cookie lifetime to the minimum (one minute)
  4. Commit the configuration.
On Portal GUI: Network > GlobalProtect  > Portal > Agent > (select the agent) > Authentication > click on "Generate cookie for authentication override"
User-added image

On Gateway GUI: Network > GlobalProtect  > Gateways > Agent > (select the agent) > Client Settings > Authentication Override > Accept cookie for authentication override"
User-added image


Additional Information


https://live.paloaltonetworks.com/t5/general-topics/globalprotect-requires-token-twice-possible-rsa-inconvenience/td-p/166905

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MACCA2&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language