<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561302#M4499</link>
    <description>&lt;P&gt;The pattern is they try nonsense users such as "cisco" and I block their IP they come from, but they always come back. I am getting frequent attempts with various other users, but they seem to come back within an hour of me blocking their IPs.&lt;BR /&gt;&lt;BR /&gt;I need a rule that immediately blocks the user, potentially one that could add to a dynamic IP list discouraging return visits, BUT I'd be HAPPY if the user tries with "cisco" is rejected and the connection dropped. My Policy contains the users, but I'm afraid the timing is off since this isn't a "Connection" policy, but a reaction policy.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 15:14:45 GMT</pubDate>
    <dc:creator>AndrewBytes</dc:creator>
    <dc:date>2023-10-11T15:14:45Z</dc:date>
    <item>
      <title>HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561302#M4499</link>
      <description>&lt;P&gt;The pattern is they try nonsense users such as "cisco" and I block their IP they come from, but they always come back. I am getting frequent attempts with various other users, but they seem to come back within an hour of me blocking their IPs.&lt;BR /&gt;&lt;BR /&gt;I need a rule that immediately blocks the user, potentially one that could add to a dynamic IP list discouraging return visits, BUT I'd be HAPPY if the user tries with "cisco" is rejected and the connection dropped. My Policy contains the users, but I'm afraid the timing is off since this isn't a "Connection" policy, but a reaction policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 15:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561302#M4499</guid>
      <dc:creator>AndrewBytes</dc:creator>
      <dc:date>2023-10-11T15:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561326#M4500</link>
      <description>&lt;P&gt;Welcome to the club. 2FA and limiting login by geographic location is the only thing you can do, I believe.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's nothing like Fail2ban that will do what you're wanting.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561326#M4500</guid>
      <dc:creator>MNoble</dc:creator>
      <dc:date>2023-10-11T18:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561361#M4502</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231619"&gt;@AndrewBytes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have found that disabling the portal login page (under the General tab) has removed 99% of those attempts.&amp;nbsp; You can re-enable it temporarily if someone needs to download the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 11:01:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561361#M4502</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-12T11:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561502#M4507</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231619"&gt;@AndrewBytes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have found that disabling the portal login page (under the General tab) has removed 99% of those attempts.&amp;nbsp; You can re-enable it temporarily if someone needs to download the client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I know I'm asking a dumb question, but this absolutely won't block the VPN client we have coming in?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am getting "scanned" a lot - I wanna get rid of those guys too - they make me grumpy!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 17:08:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561502#M4507</guid>
      <dc:creator>AndrewBytes</dc:creator>
      <dc:date>2023-10-12T17:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: HELP - I have a hacker trying to use SPECIFIC users to get into my VPN service</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561503#M4508</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231619"&gt;@AndrewBytes&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Correct.&amp;nbsp; My portal login page is disabled, and GP works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The bots irritate me, too, or they did.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 17:13:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/help-i-have-a-hacker-trying-to-use-specific-users-to-get-into-my/m-p/561503#M4508</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-10-12T17:13:11Z</dc:date>
    </item>
  </channel>
</rss>

