<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Authentication Destination is 0.0.0.0 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-destination-is-0-0-0-0/m-p/557132#M113063</link>
    <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a SIEM use case for VPN login failures followed by success to the same user after 5 failures.&lt;/P&gt;
&lt;P&gt;When I check the event, I could see the source is external IP as expected and destination is 0.0.0.0 and with our internal VPN gateway IP alternatively.&lt;/P&gt;
&lt;P&gt;Here I am getting confusion should I consider the destination IP 0.0.0.0 also or we can ignore it for failures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-footer"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-16 lia-quilt-column-right lia-quilt-column-message-footer-right"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;
&lt;DIV id="inlineMessageReplyContainer_1" class="lia-inline-message-reply-container lia-component-messages-widget-reply-inline-button"&gt;
&lt;DIV id="replyWrapper_1" class="lia-inline-message-reply-wrapper"&gt;
&lt;DIV id="messageActions_1" class="lia-message-actions"&gt;
&lt;DIV class="lia-button-group"&gt;&lt;SPAN class="lia-button-wrapper lia-button-wrapper-secondary"&gt;&lt;A id="link_21" class="lia-button lia-button-secondary reply-action-link lia-action-reply iconClass lia-button-slim" href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-login-failures/m-p/556193" target="_blank"&gt;Reply&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-inline-message-reply-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-moderation"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Fri, 08 Sep 2023 07:00:22 GMT</pubDate>
    <dc:creator>Arunkumar27</dc:creator>
    <dc:date>2023-09-08T07:00:22Z</dc:date>
    <item>
      <title>Global Protect Authentication Destination is 0.0.0.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-destination-is-0-0-0-0/m-p/557132#M113063</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay_1" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a SIEM use case for VPN login failures followed by success to the same user after 5 failures.&lt;/P&gt;
&lt;P&gt;When I check the event, I could see the source is external IP as expected and destination is 0.0.0.0 and with our internal VPN gateway IP alternatively.&lt;/P&gt;
&lt;P&gt;Here I am getting confusion should I consider the destination IP 0.0.0.0 also or we can ignore it for failures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-footer"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-16 lia-quilt-column-right lia-quilt-column-message-footer-right"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-right"&gt;
&lt;DIV id="inlineMessageReplyContainer_1" class="lia-inline-message-reply-container lia-component-messages-widget-reply-inline-button"&gt;
&lt;DIV id="replyWrapper_1" class="lia-inline-message-reply-wrapper"&gt;
&lt;DIV id="messageActions_1" class="lia-message-actions"&gt;
&lt;DIV class="lia-button-group"&gt;&lt;SPAN class="lia-button-wrapper lia-button-wrapper-secondary"&gt;&lt;A id="link_21" class="lia-button lia-button-secondary reply-action-link lia-action-reply iconClass lia-button-slim" href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/vpn-login-failures/m-p/556193" target="_blank"&gt;Reply&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-inline-message-reply-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-moderation"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 08 Sep 2023 07:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-destination-is-0-0-0-0/m-p/557132#M113063</guid>
      <dc:creator>Arunkumar27</dc:creator>
      <dc:date>2023-09-08T07:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Authentication Destination is 0.0.0.0</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-destination-is-0-0-0-0/m-p/557334#M113090</link>
      <description>&lt;P&gt;i'm not sure i'm visualizing your logs correctly, but i'm assuming the logs that contain 0.0.0.0 do not have a destination IP as they are system/auth logs indicating a failure rather than a connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you add (cleaned up) screenshots?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 10:58:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-destination-is-0-0-0-0/m-p/557334#M113090</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-09-11T10:58:02Z</dc:date>
    </item>
  </channel>
</rss>

