{"id":2515,"date":"2022-10-25T19:10:39","date_gmt":"2022-10-25T16:10:39","guid":{"rendered":"https:\/\/artem.services\/?p=2495"},"modified":"2022-10-26T10:47:26","modified_gmt":"2022-10-26T07:47:26","slug":"2515","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2515&lang=en","title":{"rendered":"Palo Alto VM-Series Firewall: GlobalProtect &#8212; OneLogin SAML"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2328\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png\" alt=\"\" width=\"2560\" height=\"465\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png 2560w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-300x54.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-768x140.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1536x279.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-2048x372.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-954x173.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1354x246.png 1354w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>GlobalProtect supports various authentication methods, including SAML 2.0 IdP. This example shows setting up authentication through OneLogin.<\/p>\n<h3>OneLogin<\/h3>\n<p>First, let&#8217;s add an application, for this, in the OneLogin admin interface, go to &quot;<strong>Applications<\/strong>&quot; and click &quot;<strong>Add App<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2496\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28.png\" alt=\"\" width=\"2814\" height=\"228\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28.png 2814w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-300x24.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-1024x83.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-768x62.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-1536x124.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-2048x166.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-954x77.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.28-1354x110.png 1354w\" sizes=\"(max-width: 2814px) 100vw, 2814px\" \/><\/p>\n<p>In the search bar, enter &quot;<strong>globalprotect<\/strong>&quot; and click on it<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2497\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45.png\" alt=\"\" width=\"2806\" height=\"444\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45.png 2806w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-300x47.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-1024x162.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-768x122.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-1536x243.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-2048x324.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-954x151.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.04.45-1354x214.png 1354w\" sizes=\"(max-width: 2806px) 100vw, 2806px\" \/><\/p>\n<p>In the settings, set the name of the application and click &quot;<strong>Save<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2498\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43.png\" alt=\"\" width=\"1980\" height=\"1140\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43.png 1980w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-300x173.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-1024x590.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-768x442.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-1536x884.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-954x549.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.05.43-1354x780.png 1354w\" sizes=\"(max-width: 1980px) 100vw, 1980px\" \/><\/p>\n<p>Next, in the application settings, go to the &quot;<strong>Configuration<\/strong>&quot; item, and in the &quot;<strong>Domain<\/strong>&quot; field specify the domain name for GlobalProtect.<\/p>\n<p>In the &quot;<strong>Login URL<\/strong>&quot; field, enter the following:<\/p>\n<blockquote><p>https:\/\/<strong>YOUR_GP_DOMAIN<\/strong>\/global-protect\/getsoftwarepage.esp<\/p><\/blockquote>\n<p>So that from the OneLogin portal we can get to the download page of the GlobalProtect client<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2511\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48.png\" alt=\"\" width=\"2804\" height=\"968\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48.png 2804w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-300x104.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-1024x354.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-768x265.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-1536x530.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-2048x707.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-954x329.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.17.48-1354x467.png 1354w\" sizes=\"(max-width: 2804px) 100vw, 2804px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>This completes the configuration from the OneLogin side, needs to save the changes, and downloads the SAML Metadata file. To do this, click on &quot;<strong>More Actions<\/strong>&quot; in the upper right corner and select &quot;<strong>SAML Metadata<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2499\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.50.44.png\" alt=\"\" width=\"556\" height=\"580\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.50.44.png 556w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-16.50.44-288x300.png 288w\" sizes=\"(max-width: 556px) 100vw, 556px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3>Firewall<\/h3>\n<p>Import the <strong>SAML Metadata<\/strong> file, for this go to the &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Server Profiles<\/strong>&quot; -&gt; &quot;<strong>SAML Identity Provider<\/strong>&quot; tab and select &quot;<strong>Import<\/strong>&quot; in the lower left corner<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2501\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.19.38.png\" alt=\"\" width=\"994\" height=\"580\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.19.38.png 994w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.19.38-300x175.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.19.38-768x448.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.19.38-954x557.png 954w\" sizes=\"(max-width: 994px) 100vw, 994px\" \/><\/p>\n<p>Let&#8217;s create an <strong>Authentication Profile<\/strong>, to do this, go to the &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Authentication Profile<\/strong>&quot; tab and select &quot;<strong>Add<\/strong>&quot;. Specify a name and in the &quot;<strong>IdP Server Profile<\/strong>&quot; field select the profile that was imported in the previous step, leaving all other settings as default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2513\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55.png\" alt=\"\" width=\"1190\" height=\"876\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55.png 1190w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55-300x221.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55-1024x754.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55-768x565.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-25-at-19.23.55-954x702.png 954w\" sizes=\"(max-width: 1190px) 100vw, 1190px\" \/><\/p>\n<p>Go to the &quot;<strong>Advanced<\/strong>&quot; tab and add &quot;<strong>all<\/strong>&quot; to the &quot;<strong>Allow List<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2502\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42.png\" alt=\"\" width=\"1192\" height=\"840\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42.png 1192w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42-300x211.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42-1024x722.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42-768x541.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-05-at-17.23.42-954x672.png 954w\" sizes=\"(max-width: 1192px) 100vw, 1192px\" \/><\/p>\n<p>Click &quot;<strong>OK<\/strong>&quot; and save the changes, for this, click &quot;<strong>Commit<\/strong>&quot; in the upper right corner. Now we can use this <strong>Authentication Profile<\/strong> to authenticate with GlobalProtect.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; GlobalProtect supports various authentication methods, including SAML 2.0 IdP. This example shows setting up authentication through OneLogin. OneLogin First, let&#8217;s add an application, for this, in the OneLogin admin interface, go to &quot;Applications&quot; and click &quot;Add App&quot; In the search bar, enter &quot;globalprotect&quot; and click on it In the settings, set the name of &hellip; <a href=\"https:\/\/artem.services\/?p=2515&#038;lang=en\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;Palo Alto VM-Series Firewall: GlobalProtect &#8212; OneLogin SAML&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1335],"tags":[1899,1901,1919,1905,1921],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2515"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2515"}],"version-history":[{"count":4,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2515\/revisions"}],"predecessor-version":[{"id":2520,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2515\/revisions\/2520"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2515"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2515"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2515"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}