<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find IP address of user connecting to GlobalProtect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-ip-address-of-user-connecting-to-globalprotect-vpn/m-p/508604#M105899</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133391"&gt;@FelixO&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;On the GP logs on the firewall, you'll find a field for public_ip that will give you this information. If you're planning on looking at this information, I'd highly recommend building out a script and using the API to validate this information for those that connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I would make this expanded a bit. Verify that the IPs connecting to your network are coming from where you expect them, sending alerts if it's from a location that you wouldn't expect. I'd personally not automatically block identified addresses, you'll have people connecting from random locations if they use a consumer VPN and connect to your Portal or gateway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd have a second script, or the same one, that pays vastly more attention to the recorded machinename of connected clients. If that machine name changes I send alerts to relevant people to verify the endpoint and the user connecting. I find this information is better at identifying abnormal connections than simply paying attention to the IP that the user is connecting from; once you add in the required exceptions for expected locations it's easy to see ways someone with phished credentials or malicious intentions could bypass your other checks.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2022 20:02:54 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-07-12T20:02:54Z</dc:date>
    <item>
      <title>How to find IP address of user connecting to GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-ip-address-of-user-connecting-to-globalprotect-vpn/m-p/508559#M105885</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can someone tell me how to find the home IP address of a user who has connected to GlobalProtect?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I want to be able to audit GlobalProtect connections to ensure that they are coming from the actual home network of the user rather than from the IP address of an attacker.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 13:25:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-ip-address-of-user-connecting-to-globalprotect-vpn/m-p/508559#M105885</guid>
      <dc:creator>FelixO</dc:creator>
      <dc:date>2022-07-12T13:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to find IP address of user connecting to GlobalProtect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-ip-address-of-user-connecting-to-globalprotect-vpn/m-p/508604#M105899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133391"&gt;@FelixO&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;On the GP logs on the firewall, you'll find a field for public_ip that will give you this information. If you're planning on looking at this information, I'd highly recommend building out a script and using the API to validate this information for those that connect.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I would make this expanded a bit. Verify that the IPs connecting to your network are coming from where you expect them, sending alerts if it's from a location that you wouldn't expect. I'd personally not automatically block identified addresses, you'll have people connecting from random locations if they use a consumer VPN and connect to your Portal or gateway.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd have a second script, or the same one, that pays vastly more attention to the recorded machinename of connected clients. If that machine name changes I send alerts to relevant people to verify the endpoint and the user connecting. I find this information is better at identifying abnormal connections than simply paying attention to the IP that the user is connecting from; once you add in the required exceptions for expected locations it's easy to see ways someone with phished credentials or malicious intentions could bypass your other checks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 20:02:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-ip-address-of-user-connecting-to-globalprotect-vpn/m-p/508604#M105899</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-07-12T20:02:54Z</dc:date>
    </item>
  </channel>
</rss>

