• PingFederate is installed and configured.
  • NGFW is installed and configured.
  • You have a GlobalProtect portal certificate.
  • You have a Certificate Profile.
  • You have an identity provider (IdP) certificate signed by a certificate authority (CA), and trusted by the NGFW device (recommended).

You can combine GlobalProtect VPN with PingFederate for SSO as illustrated in the following diagram.

A flowchart showing the relationship between GlobalProtect, PingFederate, and PingID.

Flow diagram that links to three tasks: Export the SAML Metadata from PingFederate, Configure a SAML integration with PingFederate in NGFW, and Import the NGFW metadata into PingFederate