<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures? in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/ta-p/574451</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Automatically blocking IP's after a certain number of Global Protect pre-login failures? " href="https://live.paloaltonetworks.com/t5/general-topics/automatically-blocking-ip-s-after-a-certain-number-of-global/m-p/565062" target="_blank" rel="noopener"&gt;Automatically blocking IP's after a certain number of Global Protect pre-login failures? &lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176255"&gt;@pomologist&lt;/a&gt;&lt;/STRONG&gt; and answered by Cyber Elite&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; and &lt;STRONG&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7011"&gt;@MikeGill&lt;/a&gt;&lt;/STRONG&gt;. Read on if you are curious about how protecting your GP from brute force attacks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I've just recently started getting blasted with Global Protect portal pre-login failures, coming from a bunch of illegitimate IP's. They all fail because I use certificate authentication and the client cert is not present on the attacker's device. &amp;nbsp;I have have the NGF set up to email me every time this happens and I'm getting just blasted with emails. I only use Global Protect for remote management.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See screenshot of some of the IP's attempting to gain access. &amp;nbsp;I keep blocking IP's but then the attacker uses new ones.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2023-11-09 at 3.50.24 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56868iA2C65C276BBF852B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-09 at 3.50.24 PM.png" alt="Screenshot 2023-11-09 at 3.50.24 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, is there a way to automatically block IP's after a certain number of Global Protect pre-login failures?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Automatic remediation of failed logins is something that I always script through the API. The easiest way to do that is creating a custom report on the firewall and using the API to collect the report on a scheduled basis. Have the script parse the IPs that are failing to login and add it to an EDL that you have configured to on the firewall and create a security rulebase entry to drop all traffic from any IP address located within the EDL.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I am new to scripting and the API.&amp;nbsp; Where do you go on the firewall for this?&amp;nbsp; I have found this type of traffic and would sure like to get it blocked a different way then manually blocking them one at a time.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Here's an article that&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class="richTextArea slds-text-longform tile__title red-txt"&gt;describes the steps to configure a security policy to block brute force attacks (excessive number of login attempts in a sort period)&amp;nbsp; on the GlobalProtect Portal page &lt;/SPAN&gt;&lt;/SPAN&gt;without having to know any scripting:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ2CAK" target="_blank" rel="noopener"&gt;Detecting Brute Force Attack on GlobalProtect Portal Page - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 26 Nov 2024 23:38:25 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2024-11-26T23:38:25Z</dc:date>
    <item>
      <title>Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/ta-p/574451</link>
      <description>&lt;P&gt;A Nominated Discussion&amp;nbsp;&lt;SPAN&gt;on implementing automatic safeguards for GlobalProtect against brute force attacks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 23:38:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/ta-p/574451</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-11-26T23:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/593243#M737</link>
      <description>&lt;P&gt;I also have the same issue. Is there a way PA automatically block the IP participating in Brute force attack?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2024 11:48:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/593243#M737</guid>
      <dc:creator>B.ZafarIqbal</dc:creator>
      <dc:date>2024-07-28T11:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/593267#M738</link>
      <description>&lt;P&gt;To my knowledge this is the only semi-automatic way.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ2CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ2CAK&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 05:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/593267#M738</guid>
      <dc:creator>Andrian</dc:creator>
      <dc:date>2024-07-29T05:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/639367#M759</link>
      <description>&lt;DIV dir="ltr"&gt;
&lt;P&gt;Why not use Auto Tagging to tag the users/source ip based on the logs and by adding them to Dynamic User Group (DUG)&amp;nbsp; and block them? It can be combined with the brute force signature as to trigger from it's log!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-auto-tagging-to-automate-security-actions" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-auto-tagging-to-automate-security-actions&amp;amp;source=gmail&amp;amp;ust=1732185061613000&amp;amp;usg=AOvVaw1CXtUEcoLFi_fjUvUzFJpU"&gt;Use Auto-Tagging to Automate Security Actions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/dynamic-user-groups" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/network-security/security-policy/administration/objects/dynamic-user-groups&amp;amp;source=gmail&amp;amp;ust=1732185061613000&amp;amp;usg=AOvVaw3lriya0iq0ZgROJlyU53vq"&gt;Policy Object: Dynamic User Groups&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-dynamic-user-groups-in-policy" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/use-dynamic-user-groups-in-policy&amp;amp;source=gmail&amp;amp;ust=1732185061613000&amp;amp;usg=AOvVaw2N5WpWk78lfQK0EEqPwxn7"&gt;Use Dynamic User Groups in Policy&lt;/A&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 20 Nov 2024 10:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/639367#M759</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2024-11-20T10:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Nominated Discussion - Automatically blocking IP's after a certain number of Global Protect pre-login failures?</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/998794#M769</link>
      <description>&lt;P&gt;Configuring the vulnerability protection profile exclusion for global protect and set the action to IP-block is the best way to do this.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 14:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/nominated-discussion-automatically-blocking-ip-s-after-a-certain/tac-p/998794#M769</guid>
      <dc:creator>JonGross</dc:creator>
      <dc:date>2024-12-18T14:52:02Z</dc:date>
    </item>
  </channel>
</rss>

