SecureW2 Brings Phishing-Resistant Certificates to Palo Alto’s VPN

SecureW2 extends certificate-based trust to your Palo Alto environment, delivering phishing-resistant passwordless access backed by a proven PKI foundation. Deploy Certificate Distribution for SSL Inspection to manage encrypted traffic, maintain full network visibility, and enforce identity policies across all managed and BYOD devices without disruption.

Overview

Certificate-Backed Access for Palo Alto Firewalls, Without the EAP-TLS Wait

SecureW2 provides PKI and RADIUS for Palo Alto, issuing device-bound, phishing-resistant certificates via JoinNow self-service onboarding. Since firewalls can’t accept EAP-TLS over RADIUS directly, SecureW2 bridges this gap by integrating its CA with Palo Alto Networks for trust or by running JoinNow Cloud RADIUS with policies that evaluate identity, role, and device posture, layering MFA through SAML. It manages the entire certificate lifecycle, enabling real-time revocation if an IdP, MDM, or EDR flags a device as risky. Once Palo Alto supports native EAP-TLS over RADIUS, the PKI setup is ready.

Use Cases
NPS / On-Premises RADIUS Replacement
Dynamic VLAN Assignment from Identity Attributes
Video Overview

See the Integration in Action

Want to See More Demos, Click Here

How It Works

Two Paths to Trusted Identity on Palo Alto

VPN Authentication Flow with Real-Time Identity Lookup​

The device presents its certificate to the Palo Alto Networks VPN gateway, which forwards the request to Cloud RADIUS via RADIUS. Cloud RADIUS validates the certificate and performs a live identity provider lookup to confirm the user’s status and group membership. It returns a RADIUS Accept to the gateway, which then establishes the encrypted tunnel. A deprovisioned user is blocked from subsequent connection attempts without certificate revocation.

Certificate Distribution for SSL Inspection (SSLI)

JoinNow automates SSL inspection certificate distribution across Windows, macOS, iOS, Android, and ChromeOS through self-service onboarding. Devices receive and trust the Palo Alto Networks’ inspection certificate automatically, eliminating browser warnings and manual installation across managed and BYOD fleets.

Use Cases

Deployment & Architecture Detail

NPS / On-Premises RADIUS Replacement

Organizations running WPA2-Enterprise on Palo Alto often depend on on-premises NPS servers and Active Directory Certificate Services to authenticate devices. SecureW2 eliminates that infrastructure dependency. Cloud RADIUS authenticates directly against the configured identity provider: no NPS, no domain controller, no AD CS in the path.

 

During enrollment, the Policy Engine validates user identity before issuing a certificate. At authentication time, Cloud RADIUS performs a live identity provider lookup, verifying account status and group membership, and returns the appropriate RADIUS response to Palo Alto. The full path runs through Cloud RADIUS and the identity provider, not on-premises infrastructure. NPS and AD CS can be decommissioned without affecting Wi-Fi or VPN access.

 

Branch offices and remote users authenticate the same way. Because the authentication path runs through Cloud RADIUS rather than on-premises servers, there is no dependency on domain controller reachability, VPN tunnels to reach NPS, or AD replication health.

Dynamic VLAN Assignment from Identity Attributes

Cloud RADIUS reads identity provider group membership at authentication time and maps group values to RADIUS policy attributes, including VLAN assignments. Each rule specifies a group condition and the RADIUS attributes to return when that condition is met.

 

Group-to-VLAN rules are defined once in Cloud RADIUS. Identity provider group management automatically drives network access. When a user moves between groups, the change takes effect at the next authentication event, no manual RADIUS policy changes required.

Frequently Asked Questions

Palo Alto Networks Integration — Common Questions

How long does it take to set up the SecureW2 and Palo Alto Integration?

Most organizations can configure the integration in a single session by following our setup guide and working with our knowledgeable engineers. Once complete, users begin authenticating with certificates instead of passwords without requiring major changes to existing Palo Alto configurations.

Which authentication protocols are supported?

Unlike Wi‑Fi enterprise networks, many VPNs, including Palo Alto’s, do not yet natively support EAP‑TLS certificate authentication over RADIUS. To address this, SecureW2 provides two pathways. With Cloud RADIUS and MFA, VPN sessions can be authenticated via SAML, assigning users a unique username/password and automatically prompting for MFA. Alternatively, with SecureW2 Managed PKI, organizations can integrate our certificate authorities directly into their firewall, establishing a certificate chain of trust without relying on EAP‑TLS. Both methods give administrators flexible, secure options to remove traditional passwords from the VPN login process.

How does passwordless VPN authentication look from the end-user perspective?

From the user’s perspective, connecting to Palo Alto VPN with SecureW2 is no different from opening the GlobalProtect client and clicking “connect.” The difference is behind the scenes: instead of typing a username or password, the session is authenticated automatically with a certificate issued to their device. This creates a frictionless login experience where users connect instantly and securely, without having to remember or reset passwords.

How does certificate revocation work if a device is lost, stolen, or flagged by an EDR?

SecureW2 continuously manages the full lifecycle of VPN certificates. If a device is reported lost, stolen, or flagged by endpoint security tools, its certificate is revoked using cloud‑based PKI controls. Administrators can choose to suspend it temporarily (with the option to restore later) or revoke it fully, which updates the CRL and blocks VPN access. This minimizes exposure while giving IT teams flexible control to reinstate secure access once the device is remediated.

Does Palo Alto support certificate-based RADIUS authentication?

Currently, Palo Alto VPN does not support EAP‑TLS certificate authentication directly over RADIUS. SecureW2 offers two integration paths: using Cloud RADIUS with MFA to secure VPN logins with an identity‑bound, MFA‑protected credential, or deploying Managed PKI to establish a certificate trust chain within Palo Alto firewalls. Both methods provide strong security today and ensure that when Palo Alto adds EAP‑TLS support in the future, your organization will already have the full PKI infrastructure in place.

Ready to Connect Palo Alto Integration to SecureW2?

Connect with our integration specialists to implement this solution in your environment and transform your security posture.