To use
Multi-Factor
Authentication (MFA) for protecting sensitive services and
applications, you must configure Authentication Portal to display
a web form for the first authentication factor and to record
Authentication
Timestamps. The firewall uses the timestamps to evaluate
the timeouts for
Authentication
Policy rules. To enable additional authentication factors,
you can integrate the firewall with MFA vendors through RADIUS or
vendor APIs. After evaluating Authentication policy, the firewall
evaluates Security policy, so you must configure rules for both policy
types.
Palo Alto Networks provides support for
MFA vendors through Applications content
updates. This means that if you use Panorama to push device group
configurations to firewalls, you must
install the same Applications
updates on the firewalls as on Panorama to avoid mismatches
in vendor support.
MFA vendor API integrations are supported
for end-user authentication through Authentication Policy only.
For remote user authentication to GlobalProtect portals or gateways
or for administrator authentication to the PAN-OS or Panorama web
interface, you can only use MFA vendors supported through RADIUS or
SAML; MFA services through vendor APIs are not supported in these
use cases.