I'm in the middle of a project to integrate the MFA in the VPN login process. We are using a PA-500 Next Gen Firewall from Palo Alto Networks. They have a multistep vpn login, in which you authenticate at least twice. I have left the first part of the login with standard AD integrated Radius auth. The second part will use the same username, but will auth against the YubiRadius. I can not get a good auth through the global protect agent, even though I can through the troubleshooter and through the admin login for the firewall itself.
Anyone tried this or have any insights? Seems like this should be straight forward, I'm working with their tech support, but it's slow going. Just want to make sure I didn't miss anything.
--Charles
|