The following procedure shows how to set up Authentication Portal authentication
by configuring the PAN-OS integrated User-ID agent to redirect web requests that
match an
Authentication
Policy rule to a firewall interface (redirect host).
Based on
their sensitivity, the applications that users access through Authentication Portal
require different authentication methods and settings. To accommodate all
authentication requirements, you can use default and custom authentication
enforcement objects. Each object associates an Authentication rule with an
authentication profile and an Authentication Portal authentication method.
Default authentication enforcement objects—Use the default objects if
you want to associate multiple Authentication rules with the same global
authentication profile. You must
configure this authentication profile before
configuring Authentication Portal, and then assign it in the Authentication
Portal Settings. For Authentication rules that require
Multi-Factor Authentication (MFA), you cannot use default
authentication enforcement objects.
Custom authentication enforcement objects—Use a custom object for each
Authentication rule that requires an authentication profile that differs
from the global profile. Custom objects are mandatory for Authentication
rules that require MFA. To use custom objects, create authentication
profiles and assign them to the objects after configuring Authentication
Portal—when you
Configure
Authentication Policy.
Keep in mind that authentication profiles are necessary only if users
authenticate through a Authentication Portal
Web Form or
Kerberos SSO.
Alternatively, or in addition to these methods, the following procedure also
describes how to implement
Client Certificate
Authentication.
If you use Authentication Portal without the
other User-ID functions (user mapping and group mapping), you don’t need to
configure a User-ID agent.