<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP Portal logs showing local password guessing attempts even though I'm using Azure IdP. Should I be concerned? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-portal-logs-showing-local-password-guessing-attempts-even/m-p/582665#M5221</link>
    <description>&lt;P&gt;I have our portal set up to use Azure for logon, and it's been working great. Lately I'm seeing many of these attempts in the system logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. saml-client-redirect, "Client '95.164.0.25' redirected to '&lt;A href="https://login.microsoftonline.com/xxxxxxxxx/saml2" target="_blank" rel="noopener"&gt;https://login.microsoftonline.com/xxxxxxxxx/saml2&lt;/A&gt;' for authentication profile "Azure"&lt;/P&gt;
&lt;P&gt;2. auth-fail, Failed authentication for user 'lakiesha'. Reason: Internal error, e.g. network connection, DNS failure or remote server down. auth profile 'Azure', vsys 'vsys1', From: 95.164.0.25&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like it's sending them to Azure, but then returning to the firewall again and trying to login as a local user. But why is there a internal error/DNS failure error message?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2024 15:56:33 GMT</pubDate>
    <dc:creator>Maxstr</dc:creator>
    <dc:date>2024-04-04T15:56:33Z</dc:date>
    <item>
      <title>GP Portal logs showing local password guessing attempts even though I'm using Azure IdP. Should I be concerned?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-portal-logs-showing-local-password-guessing-attempts-even/m-p/582665#M5221</link>
      <description>&lt;P&gt;I have our portal set up to use Azure for logon, and it's been working great. Lately I'm seeing many of these attempts in the system logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. saml-client-redirect, "Client '95.164.0.25' redirected to '&lt;A href="https://login.microsoftonline.com/xxxxxxxxx/saml2" target="_blank" rel="noopener"&gt;https://login.microsoftonline.com/xxxxxxxxx/saml2&lt;/A&gt;' for authentication profile "Azure"&lt;/P&gt;
&lt;P&gt;2. auth-fail, Failed authentication for user 'lakiesha'. Reason: Internal error, e.g. network connection, DNS failure or remote server down. auth profile 'Azure', vsys 'vsys1', From: 95.164.0.25&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like it's sending them to Azure, but then returning to the firewall again and trying to login as a local user. But why is there a internal error/DNS failure error message?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 15:56:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-portal-logs-showing-local-password-guessing-attempts-even/m-p/582665#M5221</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2024-04-04T15:56:33Z</dc:date>
    </item>
  </channel>
</rss>

