<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y000096QsanSACOkta Classic EngineAdministrationAnswered2024-04-15T12:18:34.000Z2020-08-08T03:06:03.000Z2020-08-15T07:02:56.000Z

ziw0w (ziw0w) asked a question.

Using AD Groups Imported to Okta with SAML 2.0 for Palo Alto GlobalProtect VPN

Hello All

I am trying to provision the Palo Alto GlobalProtect VPN solution with an authentication profile using Okta SSO. I have SSO functional and I can successfully delineate client IP pools through Okta SAML 2.0 based on Okta userid. I cannot do so based on LDAP or Okta group memberships. The end goal is to set up AD groups based on roles to assign a client pool address that provides role based access to various segments of the network. Example: my account is in the student access group my VPN client IP is from the student pool, my assigned VPN address is only allowed access to student appropriate subnets. Has anyone successful passed a group membership attribute to a GlobalProtect client to assign them a specific pool within the GP Gateway configuration? As, I mentioned, if a manually assign users specifically they can be assigned a separate client address. Group membership has no impact on which address they receive. Is there a way to leverage either AD or LDAP integrations to bridge this gap?


This question is closed.
Loading
Using AD Groups Imported to Okta with SAML 2.0 for Palo Alto GlobalProtect VPN