To configure GlobalProtect
to support dynamic passwords—such as one-time passwords (OTPs)—specify
the portal or gateway types that require users to enter dynamic
passwords. Where two-factor authentication is not enabled, GlobalProtect
uses regular authentication using login credentials (such as AD)
and a certificate. When you enable a portal or a gateway type
for two-factor authentication, that portal or gateway prompts the
user after initial portal authentication to submit credentials and
a second OTP (or other dynamic password). However, if you
also enable authentication override, an encrypted cookie is used
to authenticate the user (after the user is first authenticated
for a new session) and, thus, preempts the requirement for the user
to re-enter credentials (as long as the cookie is valid). Therefore,
the user is transparently logged in whenever necessary as long as
the cookie is valid. You specify the lifetime of the cookie. |