<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting Failed Attempts and Lockout Time in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559894#M4451</link>
    <description>&lt;P&gt;Thanks Raido&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try the vulnerability Profile. When I go to the Auth profile and advanced, I am only seeing the allow list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MJF&lt;/P&gt;</description>
    <pubDate>Thu, 28 Sep 2023 16:26:38 GMT</pubDate>
    <dc:creator>MFacella1</dc:creator>
    <dc:date>2023-09-28T16:26:38Z</dc:date>
    <item>
      <title>Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559709#M4441</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to set f&lt;SPAN&gt;ailed attempts and lockout time on my Global Protect auth profile&amp;nbsp;but I do not see where I can set this. The only place I see these settings is in the global profile but I would like to set this only&amp;nbsp;for Global&amp;nbsp;Protect. I am using v&amp;nbsp;10.2.4-h2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for any&amp;nbsp;&lt;/SPAN&gt;thoughts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MJF&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 15:29:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559709#M4441</guid>
      <dc:creator>MFacella1</dc:creator>
      <dc:date>2023-09-27T15:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559871#M4448</link>
      <description>&lt;P&gt;Lockoud time can be configured at&amp;nbsp;&lt;BR /&gt;Device &amp;gt; Authentication Profile &amp;gt; Auth-Profile-Name &amp;gt; Advanced tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also adjust vulnerability signature 40017 (Objects &amp;gt; Security Profiles &amp;gt; Vulnerability protection) if source IP should be blocked after specific number of failed login attempts.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559871#M4448</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-28T13:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559891#M4450</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If your GP uses something like active directory, you could use a GPO to set something like, lockout after &amp;lt;&amp;gt; failed attempts and unlock after &amp;lt;&amp;gt;minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 16:16:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559891#M4450</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-28T16:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559894#M4451</link>
      <description>&lt;P&gt;Thanks Raido&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will try the vulnerability Profile. When I go to the Auth profile and advanced, I am only seeing the allow list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MJF&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 16:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559894#M4451</guid>
      <dc:creator>MFacella1</dc:creator>
      <dc:date>2023-09-28T16:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559896#M4452</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1695918490275.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54039i50D8CA7CFF350568/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1695918490275.png" alt="Raido_Rattameister_0-1695918490275.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SAML Profile for example don't have this option. You need to configure lockout on SAML/2FA provider side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 16:30:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/559896#M4452</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-28T16:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/560406#M4466</link>
      <description>&lt;P&gt;Can you provide details on how to do that?&amp;nbsp; I've seen ID 40017 mentioned in older documentation but can't find anything that references how to do it.&amp;nbsp; I'm trying to block IPs after a certain number of failed GP portal login attempts - I've got numerous brute force attempts happening.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 19:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/560406#M4466</guid>
      <dc:creator>DSharretts</dc:creator>
      <dc:date>2023-10-03T19:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Failed Attempts and Lockout Time</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/560416#M4467</link>
      <description>&lt;P&gt;If you go to Objects security profiles you can create a vulnerability profile there. If you add a vulnerability profile you can go to Exceptions and check all signatures then search for 40017 to edit. I was able to stop the brute force attacks by disabling the VPN web portal page because all my VPN users are using the client.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 21:11:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/setting-failed-attempts-and-lockout-time/m-p/560416#M4467</guid>
      <dc:creator>MFacella1</dc:creator>
      <dc:date>2023-10-03T21:11:52Z</dc:date>
    </item>
  </channel>
</rss>

