Integrate with Palo Alto Networks Next-Generation Firewall
Support level: Community
What is Palo Alto Networks Next-Generation Firewall?
Palo Alto Networks Next-Generation Firewall runs PAN-OS and provides network security controls and a web interface for firewall administration.
-- https://www.paloaltonetworks.com/network-security/next-generation-firewall
Preparation
This guide configures SAML sign-in to the PAN-OS firewall management web interface. For GlobalProtect portals and gateways, see the GlobalProtect integration guide.
The following placeholders are used in this guide:
authentik.companyis the FQDN of the authentik installation.
You need administrative access to authentik and PAN-OS, an HTTPS management interface, a certificate in authentik for signing SAML responses, and a certificate in PAN-OS for signing SAML requests. Keep a local PAN-OS administrator account available while testing SAML sign-in.
authentik configuration
Create an application and SAML provider in authentik. PAN-OS exports its service provider metadata only after you configure an authentication profile, so you will replace the temporary ACS URL after importing the authentik metadata into PAN-OS.
Create an application and provider
authentik 2026.5 introduces changes to how the SAML provider behaves. Specifically, the provider now automatically sets the Issuer value to: https://authentik.company/application/saml/<application_slug>/metadata/
Older versions of authentik set this value to authentik by default. If you're running an older version, please set Issuer to https://authentik.company/application/saml/<application_slug>/metadata/, where <application_slug> is the slug that you selected for the application.
- Log in to authentik as an administrator and open the authentik Admin interface.
- Navigate to Applications > Applications and click New Application.
- Application: provide a descriptive name. Note the Slug value.
- Choose a Provider type: select SAML Provider.
- Configure the Provider: provide a name and select an authorization flow. Set ACS URL to
https://temp.tempfor now. Under Advanced protocol settings, select a Signing Certificate, enable Sign responses, and add authentik default SAML Mapping: Username to Selected User Property Mappings. - Configure Bindings (optional): bind users, groups, or policies to control access to the application.
- Click Submit.
Download the identity provider metadata
- Navigate to Applications > Providers and open the provider that you created.
- Under Metadata, click Download. You will import this file into PAN-OS.
Palo Alto Networks Next-Generation Firewall configuration
Import the SAML identity provider
- Log in to the PAN-OS management web interface.
- Navigate to Device > Server Profiles > SAML Identity Provider and click Import.
- Enter a Profile Name, such as
authentik, and select the downloaded file for Identity Provider Metadata. - If a certificate authority issued the authentik signing certificate, keep Validate Identity Provider Certificate selected and configure a PAN-OS certificate profile that trusts that authority. If the signing certificate is self-signed, clear this option. PAN-OS still checks SAML message signatures against the certificate in the imported metadata.
- Click OK.
Create and assign an authentication profile
- Navigate to Device > Authentication Profile and click Add.
- Enter a Name, set Type to SAML, and select the authentik profile for IdP Server Profile.
- Select a Certificate for Signing Requests. If you enabled Validate Identity Provider Certificate, select the certificate profile that trusts the authentik signing certificate for Certificate Profile.
- Set Username Attribute to
http://schemas.goauthentik.io/2021/02/saml/username. - On the Advanced tab, add the administrators who can use this profile to the Allow List, then click OK.
- Navigate to Device > Administrators. Open each administrator account that will use SAML, select the new Authentication Profile, and confirm that its Name matches the authentik username sent in the SAML assertion.
- Commit the changes.
Export the PAN-OS service provider metadata
- Navigate to Device > Authentication Profile and click Metadata in the authentication profile's Authentication column.
- Set Service to
managementand select the interface used for management access under Management Choice. - Click OK and save the metadata XML file. You will use its
entityIDandAssertionConsumerServiceLocationvalues in authentik.
Update the authentik provider
- In the authentik Admin interface, navigate to Applications > Providers and edit the provider that you created.
- Set ACS URL to the
Locationvalue of the PAN-OS metadata'sAssertionConsumerServiceelement that uses the HTTP-POST binding. - Set Audience to the
entityIDvalue of the PAN-OS metadata'sEntityDescriptorelement. - Set Service Provider Binding to Post and save the provider.
Configuration verification
Open the PAN-OS management web interface, click Use Single Sign-On, and enter the username of an administrator assigned to the SAML authentication profile. Complete the authentik sign-in flow. PAN-OS should return to the management web interface with that administrator's permissions.