Paloalto Firewall GlobalProtect VPN 設定記錄 (Split Tunnel & Entra-ID 2FA)

GP domain: gp.abc.com
PA IP: 192.168.30.110
DNS server: 172.20.30.150

 

PA只有一個Interface e1/1: 192.168.30.110

首先先設定Local Authentication

Import gp.abc.com的證書和其他ca/intermediate等等的cert

建立及選擇剛才Import的Certicate

e1/1是listen GP interface, 如果有untrust的通常會選擇untrust

SSL/TLS Service Profile選擇剛才建立的GP和建立Local Authentication

加入以下subnet到client的routing table, 可以經由GP進入

內部DNS Server

SSL/TLS Service Profile還是選擇GP

External設定外部連接方法,建議用FQDN, 輸入gp.abc.com

On-demand比較適合大部份用家,需要時才用VPN

再來就是要設定,VPN user可以連接到那裏

GP已經可用

Reference

https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/globalprotect%E7%9A%84%E8%AF%81%E4%B9%A6%E9%85%8D%E7%BD%AE-ssl-tls-%E5%AE%A2%E6%88%B7%E7%AB%AF%E8%AF%81%E4%B9%A6%E9%85%8D%E7%BD%AE%E6%96%87%E4%BB%B6-%E5%AE%A2%E6%88%B7%E7%AB%AF-%E6%9C%BA%E5%99%A8%E8%AF%81%E4%B9%A6/ta-p/527867

 

https://entra.microsoft.com/

https://gp.abc.com:443/SAML20/SP

https://gp.abc.com:443/SAML20/SP/ACS

https://gp.abc.com

Download "Federation Metadata XML"這個file

Import剛才的xml

發現問題

暫時的解決方法是unclick這個

再重做剛才的設定

把Entra ID推高, 或者刪除Local

Gateway和Portal都需要改Authentication

增加可以登入的user

現在已經可以使用entra id登入

Reference

https://learn.microsoft.com/zh-tw/entra/identity/saas-apps/palo-alto-networks-globalprotect-tutorial

 

2FA需要Conditional Access

Users or agents (Preview) -> All users

Target resources -> Select resources -> Select specific resources -> Palo Alto Networks - GlobalProtect

Access controls -> Grant -> Require authentication strength -> Multifactor authentication

Session -> Sign-in frequency -> Periodic reauthentication -> 4 Hours

再加入小許fine tune

Comments

No comments yet. Why don’t you start the discussion?

發佈留言

發佈留言必須填寫的電子郵件地址不會公開。 必填欄位標示為 *

*