<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How could i drop&amp;quot;unknown RADIUS authentication protocol&amp;quot;? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588549#M117341</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/803327649"&gt;@R.Tudon&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you should be able to use below string in the filter builder to filter these logs out:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;( description contains 'unknown RADIUS authentication protocol' )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jun 2024 22:44:14 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2024-06-02T22:44:14Z</dc:date>
    <item>
      <title>How could i drop"unknown RADIUS authentication protocol"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588546#M117338</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;Recently we were receiving in our environment alerts of failed authentications from different random IP's and random usernames, i was able to reduce them following the next article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ2CAK" target="_blank" rel="nofollow noopener noreferrer"&gt;Detecting Brute Force Attack on GlobalProtect Portal Page - Knowledge Base - Palo Alto Networks,&lt;/A&gt;&amp;nbsp;and creating a dynamic list, adding tags with forward logs, dropping these attempts and blocking the IP's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This reduced a loot, of this, but i keep getting some of them, i would like to tag also the "unknown RADIUS authentication protocol" but i don't see any similar in the log forwarding filters.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RTudon_0-1717363128954.png" style="width: 743px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60137i706BEDE2A8E60D74/image-dimensions/743x52/is-moderation-mode/true?v=v2" width="743" height="52" role="button" title="RTudon_0-1717363128954.png" alt="RTudon_0-1717363128954.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions? Regards!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 21:19:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588546#M117338</guid>
      <dc:creator>R.Tudon</dc:creator>
      <dc:date>2024-06-02T21:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: How could i drop"unknown RADIUS authentication protocol"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588549#M117341</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/803327649"&gt;@R.Tudon&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you should be able to use below string in the filter builder to filter these logs out:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;( description contains 'unknown RADIUS authentication protocol' )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 22:44:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588549#M117341</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-06-02T22:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: How could i drop"unknown RADIUS authentication protocol"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588619#M117351</link>
      <description>&lt;P&gt;I tried with all the different log types, but i get this error, should I've done other thing to make this filter work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RTudon_0-1717434573939.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60153i3A0AC0087F525AC3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RTudon_0-1717434573939.png" alt="RTudon_0-1717434573939.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 17:10:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588619#M117351</guid>
      <dc:creator>R.Tudon</dc:creator>
      <dc:date>2024-06-03T17:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: How could i drop"unknown RADIUS authentication protocol"?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588634#M117354</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/803327649"&gt;@R.Tudon&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In your example it looks like you were trying to build it out for traffic, that's not where this would go. These are system events and you'd want to modify the filter for whatever log forwarding you have enabled for your system events.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 19:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-could-i-drop-quot-unknown-radius-authentication-protocol/m-p/588634#M117354</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-06-03T19:23:24Z</dc:date>
    </item>
  </channel>
</rss>

