<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: prevent-brute-force-attacks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997299#M122472</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In addition to this, I recommend implmenting Zone Protection profiles.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2024 22:49:11 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2024-12-09T22:49:11Z</dc:date>
    <item>
      <title>prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997032#M122432</link>
      <description>&lt;P&gt;Hello Everyone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking for suggestions on how we could protect our GlobalProtect VPN. We have been seeing people trying to perform brute-force attacks on random user accounts daily. We do have MFA set up, but is there any automation we could implement with Palo Alto Firewall to automatically block IP addresses after a certain number of failed attempts?"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 20:45:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997032#M122432</guid>
      <dc:creator>dshastri</dc:creator>
      <dc:date>2024-12-06T20:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997044#M122433</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/512113409"&gt;@dshastri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a great place to start.&amp;nbsp; &lt;A href="https://www.packetswitch.co.uk/how-to-protect-globalprotect-portal-from-brute-force-attack/" target="_blank"&gt;https://www.packetswitch.co.uk/how-to-protect-globalprotect-portal-from-brute-force-attack/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have used all of these methods.&amp;nbsp; They will significantly decrease the amount you are getting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 4th one is a vulnerability signature that does mostly what you ask.&amp;nbsp; I found it to not be as effective since most of my hackers were low and slow.&amp;nbsp; The signature only detects login attempts and not failures.&amp;nbsp; So, you can't tune it too tight or valid users may be blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GP can still be used without the portal page enabled.&amp;nbsp; (You actually can still download software by going to &lt;A href="https://your.domain.com/global-protect/getsoftwarepage.esp," target="_blank"&gt;https://your.domain.com/global-protect/getsoftwarepage.esp,&lt;/A&gt; but that's another story.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 23:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997044#M122433</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-12-06T23:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997299#M122472</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In addition to this, I recommend implmenting Zone Protection profiles.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clm9CAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 22:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997299#M122472</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-12-09T22:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997761#M122500</link>
      <description>&lt;P&gt;Thank You TomYoung the only thing I am missing from the documentation was&amp;nbsp;Blacklist IPs Using a Vulnerability Profile. Do you know if Palo Alto has a pre authentication check where if the user doesn't exist on the group, it drops the connection?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:28:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/997761#M122500</guid>
      <dc:creator>dshastri</dc:creator>
      <dc:date>2024-12-11T14:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/998548#M122562</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/512113409"&gt;@dshastri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NGFW does not know the user until authentication.&amp;nbsp; There is no pre-authentication check as far as I know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 20:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/998548#M122562</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-12-16T20:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/1236118#M124967</link>
      <description>&lt;P&gt;You need to implement rate limiter as if source IP addresses try the login page you don't need to check if the response was ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See my article :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-articles/how-to-write-palo-alto-networks-custom-vulnerability-and/ta-p/1228494" target="_blank"&gt;How to Write Palo Alto Networks Custom Vulnerability and Application Signatures with Examples | Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Aug 2025 17:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/1236118#M124967</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-08-17T17:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: prevent-brute-force-attacks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/1236355#M124989</link>
      <description>&lt;P&gt;Here is an updated article with multiple methods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000010zEJCAY&amp;amp;lang=en_US" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000010zEJCAY&amp;amp;lang=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 15:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-brute-force-attacks/m-p/1236355#M124989</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-08-20T15:40:38Z</dc:date>
    </item>
  </channel>
</rss>

