Configure two-factor authentication for GlobalProtect using one-time passwords (OTPs)
on the portal and gateways.
Use this workflow to configure two-factor authentication using one-time passwords (OTPs) on the
portal and gateways. When a user requests access, the portal or gateway prompts the
user to enter an OTP. The authentication service sends the OTP as a token to the
user’s RSA device.
Setting up a two-factor
authentication scheme is similar to setting up other types of authentication.
The two-factor authentication scheme requires you to configure:
A server profile (usually for a RADIUS service for two-factor authentication)
assigned to an authentication profile.
A client authentication profile that includes the authentication
profile for the service that these components use.
By
default, the app supplies the same credentials used to log in to
the portal and gateway. In the case of OTP authentication, this
behavior causes the authentication to initially fail on the gateway
and, because of the delay this causes in prompting the user for
a login, the user’s OTP may expire. To prevent this, you must configure
the portals and gateways that prompt for the OTP instead of using
the same credentials on a per-app configuration basis.
You
can also reduce the frequency in which users are prompted for OTPs
by configuring an authentication override. This enables the portals
and gateways to generate and accept a secure encrypted cookie to
authenticate the user for a specified amount of time. The portals
and/or gateways do not require a new OTP until the cookie expires,
thus reducing the number of times users must provide an OTP.