<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed GlobalProtect login confusion in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598309#M5842</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124896"&gt;@Steve_E&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct!&amp;nbsp; I learned also after I posted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2024 15:30:35 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-09-19T15:30:35Z</dc:date>
    <item>
      <title>Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558388#M4392</link>
      <description>&lt;P&gt;We're experiencing a very slow "brute force" login to our VPN but I'm having issues understanding how they're trying to log in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We currently use okta. None of their failed attempts are showing up in okta but they are showing up in the GlobalProtect monitoring tab of the firewall. Where could they be trying to log in (and failing) to make these logs show up? I am not able to recreate it by failing to log in.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53809i284BD25368C62B08/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 14:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558388#M4392</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2023-09-18T14:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558436#M4393</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37384"&gt;@DopedWafer&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try logging into the portal web page with bad credentials.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:22:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558436#M4393</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-18T20:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558441#M4394</link>
      <description>&lt;P&gt;When I hit our VPN page we get redirected to the Okta login, failing our logins here does not log it on the palo alto side but only in Okta. Is there a different logon page they could be getting to? It's weird to me because their failed attempts only show up on the firewall and not okta.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:31:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558441#M4394</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2023-09-18T20:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558442#M4395</link>
      <description>&lt;P&gt;Are you connecting to the portal page with a browser or GlobalProtect client?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:33:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558442#M4395</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-18T20:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558446#M4397</link>
      <description>&lt;P&gt;I am authenticating through the embedded browser in the globalprotect client which takes us to an okta log in.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:48:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558446#M4397</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2023-09-18T20:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558447#M4398</link>
      <description>&lt;P&gt;Got it.&amp;nbsp; Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Open a browser on your computer and browse to your GlobalProtect portal FQDN. e.g., &lt;A href="https://xxx.yourdoamin.com" target="_blank"&gt;https://xxx.yourdoamin.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558447#M4398</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-18T20:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558448#M4399</link>
      <description>&lt;P&gt;This also takes me to okta to authenticate, failing to log in here also does not get logged to the firewall, only the okta logs.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 20:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558448#M4399</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2023-09-18T20:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558450#M4400</link>
      <description>&lt;P&gt;Thank you for testing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was getting LOTS of the slow, brute force logins, and disabling the portal web page stopped almost all of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1695070923977.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53815iB2FB65A56C60B833/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1695070923977.png" alt="TomYoung_0-1695070923977.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was expecting the failed attempt with the browser was causing it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 21:03:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558450#M4400</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-18T21:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558594#M4402</link>
      <description>&lt;P&gt;Thanks, I disabled it and so far so good. Very bizarre to me that I could not recreate the failed login issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This brings up another question, with the portal page disable I'm not sure how to get the latest globalprotect client, normally users would navigate to the portal and log in to get it. Is there another way of getting it?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 14:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558594#M4402</guid>
      <dc:creator>DopedWafer</dc:creator>
      <dc:date>2023-09-19T14:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558612#M4404</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37384"&gt;@DopedWafer&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Users that already have the GP client can be upgraded without the page enabled.&amp;nbsp; For new GP users, you can temporarily enable the portal page, or you could push out the client through MS Intune, Jamf Pro, or similar software.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 17:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/558612#M4404</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-09-19T17:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598295#M5840</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37384"&gt;@DopedWafer&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;you can also access the Globalprotect client with the direct URL, such as &lt;A href="https://portal[.]example[.]com/global-protect/getsoftwarepage[.]esp" target="_blank"&gt;https://portal[.]example[.]com/global-protect/getsoftwarepage[.]esp&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598295#M5840</guid>
      <dc:creator>Steve_E</dc:creator>
      <dc:date>2024-09-19T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598309#M5842</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124896"&gt;@Steve_E&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct!&amp;nbsp; I learned also after I posted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598309#M5842</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-09-19T15:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed GlobalProtect login confusion</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598341#M5843</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37384"&gt;@DopedWafer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;This also takes me to okta to authenticate, failing to log in here also does not get logged to the firewall, only the okta logs.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;When you say you get redirected to Okta to authenticate, I assume you are running SAML authentication through Okta?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see continuing slow brute-force login attempts on our Portal and Gateway interfaces (that require client cert and SAML authentication respectively). What I have found is that the login attempts are scripted and are just pushing POST login/password variables or sending a HTTP authentication header with user/password. So they ignore/don't understand the initial PA server response to provide a cert/SAML token and instead blindly pushes credentials. The error login therefore shows up on the PA and not your SAML provider as the script never redirects there.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 17:11:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/failed-globalprotect-login-confusion/m-p/598341#M5843</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-09-19T17:11:09Z</dc:date>
    </item>
  </channel>
</rss>

