• PingFederate is installed and configured.
  • NGFW is installed and configured.
  • You have a GlobalProtect portal certificate.
  • You have a Certificate Profile.
  • You have an identity provider (IdP) certificate signed by a certificate authority (CA), and trusted by the NGFW device (recommended).

You can combine GlobalProtect VPN with PingFederate for SSO as illustrated in the following diagram.

A flowchart showing the relationship between GlobalProtect, PingFederate, and PingID.

Produced by OmniGraffle 7.18.5\n2021-08-03 16:50:29 +0000 Canvas 1 Layer 1 Export the SAML Metadata from PingFederate Configure a SAML integration with PingFederate in NGFW Import the NGFW Metadata into PingFederate