Configuring SSO for GlobalProtect VPN with PingFederate - PingFederate

Use Cases

bundle
solution-guides
ft:publication_title
Use Cases
Product_Version_ce
category
ContentType
howtodoc
ContentType_ce
How-to

Next-Generation Firewall (NGFW) supports the ability to enable single sign-on (SSO) through the admin UI.

  • PingFederate is installed and configured.
  • NGFW is installed and configured.
  • You have a GlobalProtect portal certificate.
  • You have a Certificate Profile.
  • You have an identity provider (IdP) certificate signed by a certificate authority (CA), and trusted by the NGFW device (recommended).

You can combine GlobalProtect VPN with PingFederate for SSO as illustrated in the following diagram.


A flowchart showing the relationship between GlobalProtect, PingFederate, and PingID.

Produced by OmniGraffle 7.18.5\n2021-08-03 16:50:29 +0000 Canvas 1 Layer 1 Export the SAML Metadata from PingFederate Configure a SAML integration with PingFederate in NGFW Import the NGFW Metadata into PingFederate