{"id":2541,"date":"2022-10-26T15:37:52","date_gmt":"2022-10-26T12:37:52","guid":{"rendered":"https:\/\/artem.services\/?p=2521"},"modified":"2022-10-26T16:19:49","modified_gmt":"2022-10-26T13:19:49","slug":"2541","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2541&lang=en","title":{"rendered":"Palo Alto VM-Series Firewall: GlobalProtect &#8212; AWS SAML"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2328\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png\" alt=\"\" width=\"2560\" height=\"465\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png 2560w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-300x54.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-768x140.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1536x279.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-2048x372.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-954x173.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1354x246.png 1354w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>GlobalProtect supports various authorization methods, including SAML 2.0 IdP. This example shows how to set up authorization using AWS SSO.<\/p>\n<h3>AWS<\/h3>\n<blockquote><p>Before adding SAML IdP, you must already have <a href=\"https:\/\/aws.amazon.com\/directoryservice\/\" target=\"_blank\" rel=\"noopener\">AWS Directory Service<\/a> configured<\/p><\/blockquote>\n<p>To begin with, let&#8217;s add an application, for this go to &quot;<strong>IAM Identity Center<\/strong>&quot; -&gt; &quot;<strong>Application assignments<\/strong>&quot; -&gt; &quot;<strong>Application<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2522\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.41.png\" alt=\"\" width=\"538\" height=\"756\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.41.png 538w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.41-213x300.png 213w\" sizes=\"(max-width: 538px) 100vw, 538px\" \/><\/p>\n<p>And click\u00a0&quot;<strong>Add Application<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2523\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49.png\" alt=\"\" width=\"2068\" height=\"356\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49.png 2068w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-300x52.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-1024x176.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-768x132.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-1536x264.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-2048x353.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-954x164.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.19.49-1354x233.png 1354w\" sizes=\"(max-width: 2068px) 100vw, 2068px\" \/><\/p>\n<p>There is no application for GlobalProtect in the list, so we indicate it will be a custom application and click &quot;<strong>Next<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2524\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11.png\" alt=\"\" width=\"2210\" height=\"776\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11.png 2210w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-300x105.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-1024x360.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-768x270.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-1536x539.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-2048x719.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-954x335.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.27.11-1354x475.png 1354w\" sizes=\"(max-width: 2210px) 100vw, 2210px\" \/><\/p>\n<p>Specify a name and description<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2525\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13.png\" alt=\"\" width=\"1594\" height=\"602\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13.png 1594w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-300x113.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-1024x387.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-768x290.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-1536x580.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-954x360.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.32.13-1354x511.png 1354w\" sizes=\"(max-width: 1594px) 100vw, 1594px\" \/><\/p>\n<p>Next, in the &quot;<strong>Application properties<\/strong>&quot; section, in the &quot;<strong>Application start URL<\/strong>&quot; field, specify the following:<\/p>\n<blockquote><p>https:\/\/<strong>YOUR_GP_DOMAIN<\/strong>\/global-protect\/getsoftwarepage.esp<\/p><\/blockquote>\n<p>In order for us to get to the GlobalProtect client download page from the AWS SSO portal<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2526\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07.png\" alt=\"\" width=\"1586\" height=\"626\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07.png 1586w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-300x118.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-1024x404.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-768x303.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-1536x606.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-954x377.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.07-1354x534.png 1354w\" sizes=\"(max-width: 1586px) 100vw, 1586px\" \/><\/p>\n<p>In the &quot;<strong>Application metadata<\/strong>&quot; section, in the &quot;<strong>Application ACS URL<\/strong>&quot; field, specify the following:<\/p>\n<blockquote><p>https:\/\/<strong>YOUR_GP_DOMAIN<\/strong>:443\/SAML20\/SP\/ACS<\/p><\/blockquote>\n<p>And &quot;<strong>Application SAML audience<\/strong>&quot;:<\/p>\n<blockquote><p>https:\/\/<strong>YOUR_GP_DOMAIN<\/strong>:443\/SAML20\/SP<\/p><\/blockquote>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2527\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47.png\" alt=\"\" width=\"1590\" height=\"638\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47.png 1590w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-300x120.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-1024x411.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-768x308.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-1536x616.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-954x383.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.33.47-1354x543.png 1354w\" sizes=\"(max-width: 1590px) 100vw, 1590px\" \/><\/p>\n<p>Then download the <strong>SAML Metadata<\/strong> file, scroll down and click &quot;<strong>Submit<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2528\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13.png\" alt=\"\" width=\"1574\" height=\"322\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13.png 1574w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-300x61.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-1024x209.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-768x157.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-1536x314.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-954x195.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.42.13-1354x277.png 1354w\" sizes=\"(max-width: 1574px) 100vw, 1574px\" \/><\/p>\n<p>After adding the application, you need to make sure that the correct attribute format is used. To do this, in the &quot;<strong>Actions<\/strong>&quot; tab, select &quot;<strong>Edit attribute mapping<\/strong>&quot;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2530\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53.png\" alt=\"\" width=\"2218\" height=\"554\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53.png 2218w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-300x75.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-1024x256.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-768x192.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-1536x384.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-2048x512.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-954x238.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-14.49.53-1354x338.png 1354w\" sizes=\"(max-width: 2218px) 100vw, 2218px\" \/><\/p>\n<p>Required format:<\/p>\n<ul>\n<li>Value: ${user.subject}<\/li>\n<li>Format: emailAddress<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2529\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08.png\" alt=\"\" width=\"2206\" height=\"808\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08.png 2206w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-300x110.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-1024x375.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-768x281.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-1536x563.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-2048x750.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-954x349.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-13.45.08-1354x496.png 1354w\" sizes=\"(max-width: 2206px) 100vw, 2206px\" \/><\/p>\n<p>This completes the configuration from the AWS side.<\/p>\n<h3>Firewall<\/h3>\n<p>Import the <strong>SAML Metadata<\/strong> file, for this go to the &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Server Profiles<\/strong>&quot; -&gt; &quot;<strong>SAML Identity Provider<\/strong>&quot; tab and select &quot;<strong>Import<\/strong>&quot; in the lower left corner<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2532\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.22.21.png\" alt=\"\" width=\"986\" height=\"574\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.22.21.png 986w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.22.21-300x175.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.22.21-768x447.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.22.21-954x555.png 954w\" sizes=\"(max-width: 986px) 100vw, 986px\" \/><\/p>\n<blockquote><p>Parameter &quot;<strong>Validate Identity Provider Certificate<\/strong>&quot; &#8212; must be disabled<\/p><\/blockquote>\n<p>Let\u2019s create an <strong>Authentication Profile<\/strong>, to do this, go to the &quot;<strong>Device<\/strong>&quot; -&gt; &quot;<strong>Authentication Profile<\/strong>&quot; tab and select &quot;<strong>Add<\/strong>&quot;. Specify a name and in the &quot;<strong>IdP Server Profile<\/strong>&quot; field select the profile that was imported in the previous step, leaving all other settings as default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2533\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37.png\" alt=\"\" width=\"1188\" height=\"874\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37.png 1188w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37-300x221.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37-1024x753.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37-768x565.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.37-954x702.png 954w\" sizes=\"(max-width: 1188px) 100vw, 1188px\" \/><\/p>\n<p>Go to the &quot;<strong>Advanced<\/strong>&quot; tab and add &quot;<strong>all<\/strong>&quot; to the &quot;<strong>Allow List<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2534\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53.png\" alt=\"\" width=\"1188\" height=\"832\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53.png 1188w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53-300x210.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53-1024x717.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53-768x538.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-26-at-15.28.53-954x668.png 954w\" sizes=\"(max-width: 1188px) 100vw, 1188px\" \/><\/p>\n<p>Click &quot;<strong>OK<\/strong>&quot; and save the changes, for this, click &quot;<strong>Commit<\/strong>&quot; in the upper right corner. Now we can use this <strong>Authentication Profile<\/strong> to authenticate with GlobalProtect.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; GlobalProtect supports various authorization methods, including SAML 2.0 IdP. This example shows how to set up authorization using AWS SSO. AWS Before adding SAML IdP, you must already have AWS Directory Service configured To begin with, let&#8217;s add an application, for this go to &quot;IAM Identity Center&quot; -&gt; &quot;Application assignments&quot; -&gt; &quot;Application&quot; And click\u00a0&quot;Add &hellip; <a href=\"https:\/\/artem.services\/?p=2541&#038;lang=en\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;Palo Alto VM-Series Firewall: GlobalProtect &#8212; AWS SAML&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[599,1335],"tags":[1899,1901,1905,1921],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2541"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2541"}],"version-history":[{"count":3,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2541\/revisions"}],"predecessor-version":[{"id":2544,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2541\/revisions\/2544"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}