Configure Palo Alto Networks VPN to use the Okta RADIUS
To configure the Palo Alto VP to use RADIUS, follow these procedures using the Palo Alto Networks RADIUS Server Profile:
- Define a RADIUS Server Profile
- Define an Authentication Profile for Okta Palo Alto RADIUS Agent
- Apply the Okta RADIUS Authentication Profile to a Gateway
- Configure the GlobalProtect Portal to use the Okta RADIUS Authentication Profile
Before you begin
- Ensure that you have the common UDP port and secret key values available.
Define a RADIUS Server Profile
- Sign in to the Palo Alto Networks Admin Console with sufficient privileges
- Go to Add to define a new RADIUS server. , and then click
-
Enter a unique profile name, and enter the following server settings:
-
Timeout (sec): 60
-
Authentication Protocol: PAP
-
Retries: 1
-
- Click Add to define a server. Enter the following settings:
Name: Unique and appropriate name
Radius Server: IP Address of the server where you installed the Okta Palo Alto RADIUS Agent.
Secret: The RADIUS Secret you defined in the Okta RADIUS App.
Port: The UDP Port you defined in the Okta Palo Alto RADIUS App.
- Click OK.
Define an Authentication Profile for Okta Palo Alto RADIUS Agent
-
Select Add to define an Authentication Profile.
and then click -
Select the Authentication tab.
- Use the default settings except for the following:
- Type: RADIUS
- Server Profile: Enter the name of the Server Profile that you defined previously.
- Click OK.
- On the Authentication Profile page, select the Advanced tab.
- Click Add to assign an Allow List. Select All from the available options.
- Click OK to save the settings.
-
Click Commit to save the Okta RADIUS Authentication Profile.
-
Open the Palo Alto Networks Administrative Shell and Test the Authentication Profile.
Apply the Okta RADIUS Authentication Profile to a Gateway
- Select and open your configured GlobalProtect Gateway.
- Select the Authentication tab to define Client Authentication Settings.
- Click Add to update Client Authentication to the Okta RADIUS Authentication Profile you just configured.
- Leave the default settings except for the following:
- Name: Unique and appropriate name
- OS: Any
- Authentication Profile: Enter the Authentication Profile that you configured earlier.
- Authentication Message: Enter appropriate instructions for end users such as "Enter sign-in credentials".
-
Click OK to save the settings.
Configure the GlobalProtect Portal to use the Okta RADIUS Authentication Profile
Note: The step applies the same settings that you applied to your GlobalProtect Gateway to the GlobalProtect Portal.
- Select and open your configured GlobalProtect Portal.
- Select the Authentication tab to define Client Authentication Settings.
- Click Add to update Client Authentication to the Okta RADIUS Authentication Profile you configured.
- Leave the default settings except for the following:
- Name: Unique and appropriate name
- OS: Any
- Authentication Profile: Enter the Authentication Profile that you configured earlier.
- Authentication Message: Enter appropriate instructions for end users such as Enter sign-in credentials.
-
Click OK to save the settings.
Click Commit to save the Okta RADIUS configuration within the Palo Alto Networks Admin Console.