<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block access to countries outside the GlobalProtect VPN in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570842#M2305</link>
    <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Traducción" data-ved="2ahUKEwiEypvq4qyDAxVscaQEHbTmClsQ3ewLegQIBRAQ"&gt;&lt;SPAN class="Y2IQFc"&gt;Good morning, reviewing the GlobalProtect logs I see brute force attacks from outside my country Spain.

I have tried to create security policies that prevent these attempts but none have matched.

In the portal configuration (external) I have tried to put Spain as high priority and the others as None but the FW does not give me that option.

I attach images of the attempts

Any ideas?

Thank you.&lt;/SPAN&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 26 Dec 2023 09:38:38 GMT</pubDate>
    <dc:creator>ccortijo</dc:creator>
    <dc:date>2023-12-26T09:38:38Z</dc:date>
    <item>
      <title>Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570842#M2305</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Traducción" data-ved="2ahUKEwiEypvq4qyDAxVscaQEHbTmClsQ3ewLegQIBRAQ"&gt;&lt;SPAN class="Y2IQFc"&gt;Good morning, reviewing the GlobalProtect logs I see brute force attacks from outside my country Spain.

I have tried to create security policies that prevent these attempts but none have matched.

In the portal configuration (external) I have tried to put Spain as high priority and the others as None but the FW does not give me that option.

I attach images of the attempts

Any ideas?

Thank you.&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 26 Dec 2023 09:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570842#M2305</guid>
      <dc:creator>ccortijo</dc:creator>
      <dc:date>2023-12-26T09:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570853#M2306</link>
      <description>&lt;P&gt;The setting on the portal is used by the clients once authenticated (which is too late on your issue).&lt;/P&gt;
&lt;P&gt;You might need to address this on the security policy which grants access to the portal (and gateway). Instead of granting "any" (or all public IPs, ...), you need to use the region "ES (Spain)" in the security policy.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 10:29:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570853#M2306</guid>
      <dc:creator>joergsch1</dc:creator>
      <dc:date>2023-12-26T10:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570854#M2307</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" data-placeholder="Traducción" data-ved="2ahUKEwjY7LvJh62DAxXSVKQEHZG6BQAQ3ewLegQIBRAQ"&gt;&lt;SPAN class="Y2IQFc"&gt;Hello,

Thanks for responding, I have a policy applied but it doesn't seem to apply.

I attach images of the GlobalProtect configuration, NAT and security policies&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 26 Dec 2023 12:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570854#M2307</guid>
      <dc:creator>ccortijo</dc:creator>
      <dc:date>2023-12-26T12:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570862#M2309</link>
      <description>&lt;P&gt;Without the column titles these are hard to read (are the titles translated to Spanish as well?).&lt;/P&gt;
&lt;P&gt;If I understand your setting correct, then you are blocking access from sources other than Spain to the portal if the application is panos-global-protect.&lt;/P&gt;
&lt;P&gt;Can you check the log entries of the brute-force access (check for application, zones, port, rule name)? The detected application might be ssl or something different. If that's the case, then your rule does not match.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 12:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570862#M2309</guid>
      <dc:creator>joergsch1</dc:creator>
      <dc:date>2023-12-26T12:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570917#M2313</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/299010"&gt;@ccortijo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traffic from the untrust zone to the interface in the &lt;STRONG&gt;same&lt;/STRONG&gt; untrust zone is allowed by the intrazone-default rule.&amp;nbsp; The easiest way to solve your problem is to create a drop rule (which will be above intrazone-default) that will drop all countries you do not want.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule Type:&amp;nbsp; intrazone&lt;/P&gt;
&lt;P&gt;Source Zone:&amp;nbsp; Untrust&lt;/P&gt;
&lt;P&gt;Source Address:&amp;nbsp; List you countries you want to allow and check Negate.&lt;/P&gt;
&lt;P&gt;Destination Address:&amp;nbsp; Portal IP (could also be any if you want to block for all public IP addresses)&lt;/P&gt;
&lt;P&gt;Application:&amp;nbsp; Any&lt;/P&gt;
&lt;P&gt;Service/URL Category:&amp;nbsp; Any&lt;/P&gt;
&lt;P&gt;Action:&amp;nbsp; Drop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can choose not to log if you don't want the clutter, but you may need to enable for troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also stop 99% of the brute force attacks by disabling the portal login page.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 23:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570917#M2313</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-12-26T23:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570943#M2314</link>
      <description>&lt;P&gt;Thank you very much for the help and the idea!&lt;/P&gt;
&lt;P&gt;I monitored a traffic log from a malicious IP that was performing brute force attacks and saw what parameters were necessary to make my policy match.&lt;/P&gt;
&lt;P&gt;It worked!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 07:11:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570943#M2314</guid>
      <dc:creator>ccortijo</dc:creator>
      <dc:date>2023-12-27T07:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570944#M2315</link>
      <description>&lt;P&gt;Thank you very much for the help!&lt;/P&gt;
&lt;P&gt;It worked!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 07:12:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/570944#M2315</guid>
      <dc:creator>ccortijo</dc:creator>
      <dc:date>2023-12-27T07:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Block access to countries outside the GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/593394#M3496</link>
      <description>&lt;P&gt;Hello Tom,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have same situation Global Protect portal is configured on WAN interface, but what ever security policy I made to block to GP Web page it is not working, I tried your advice creating intrazone policy to block specifically to tcp/443 port but it is not catching this policy.&lt;/P&gt;
&lt;P&gt;Where I'm having mistake on configuration I'm puzzled right now.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 22:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/block-access-to-countries-outside-the-globalprotect-vpn/m-p/593394#M3496</guid>
      <dc:creator>B.Alimov</dc:creator>
      <dc:date>2024-07-29T22:48:26Z</dc:date>
    </item>
  </channel>
</rss>

