<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: &amp;quot;public IP&amp;quot; in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/system-alert-opaque-failed-authentication-for-user-reason-user/m-p/548456#M1462</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've been receiving many system alerts with the message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile '', vsys 'vsys1', From" "Public IP"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventid: auth-fail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like these public IP's are trying to access our internal network by coming through Global Protect App. Coming from many different random user names and public IP addresses. It seems that the Palo Alto firewall sends the credentials to the Active Directly Server and tharts when it fails.&lt;/P&gt;
&lt;P&gt;Is there a way to prevent all these attempts without even having it go to the AD server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2023 18:16:41 GMT</pubDate>
    <dc:creator>roma</dc:creator>
    <dc:date>2023-07-06T18:16:41Z</dc:date>
    <item>
      <title>System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP"</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/system-alert-opaque-failed-authentication-for-user-reason-user/m-p/548456#M1462</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've been receiving many system alerts with the message:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile '', vsys 'vsys1', From" "Public IP"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eventid: auth-fail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It looks like these public IP's are trying to access our internal network by coming through Global Protect App. Coming from many different random user names and public IP addresses. It seems that the Palo Alto firewall sends the credentials to the Active Directly Server and tharts when it fails.&lt;/P&gt;
&lt;P&gt;Is there a way to prevent all these attempts without even having it go to the AD server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/system-alert-opaque-failed-authentication-for-user-reason-user/m-p/548456#M1462</guid>
      <dc:creator>roma</dc:creator>
      <dc:date>2023-07-06T18:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: System Alert opaque: failed authentication for user ''. Reason: User is not in allowlist. auth profile 'GP', vsys 'vsys1', From: "public IP&amp;q</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/system-alert-opaque-failed-authentication-for-user-reason-user/m-p/548520#M1463</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/116207"&gt;@roma&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The error message you receive actually tell the opposite - "Reason: User is not in allowlist"&lt;/P&gt;
&lt;P&gt;When you configure your Authentication Profile, there is a tab to specify list of users or user groups that are allowed to authenticate with that profile.&lt;/P&gt;
&lt;P&gt;Firewall will first take the provide username and compare it with this allow list. If it doesn't match any of the allowed users/user groups, FW will deny user authentication, &lt;U&gt;without&lt;/U&gt; even sending the credentials to AD for validation&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aleksandarastardzhiev_0-1688719447341.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51397i2CA6DE310B431429/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aleksandarastardzhiev_0-1688719447341.png" alt="aleksandarastardzhiev_0-1688719447341.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-authentication-profile/configure-an-authentication-profile" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-authentication-profile/configure-an-authentication-profile&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 08:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/system-alert-opaque-failed-authentication-for-user-reason-user/m-p/548520#M1463</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-07-07T08:44:25Z</dc:date>
    </item>
  </channel>
</rss>

