<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect - Clients with excessive failed logins in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220232#M63549</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Will LDAP give a return like that? When I opened a case with PA TAC they told me it wouldn't. We've only used Radius for RSA and Kerberos, so I have not tested LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using a secure cookie would reduce a login prompt. Not sure if my security team will go for it, but it's idea. Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Jul 2018 18:56:50 GMT</pubDate>
    <dc:creator>Jonathan.Bennett</dc:creator>
    <dc:date>2018-07-02T18:56:50Z</dc:date>
    <item>
      <title>Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220192#M63533</link>
      <description>&lt;P&gt;We've had Global Protect in production for a while now, but it has just recently been brought to my attention that we are having a lot of users locking their accounts out.&lt;/P&gt;&lt;P&gt;The GP client prompts them for their AD username / password. Maybe they fat-finger their password or whatever. The GP client never gives them any indication of any issue, other than just prompting for credentials again. I have users that are failing logins 30-40 times within a couple of hours. Of cource AD is locking their account out, but the end user has no idea. All they know is they are continueing to get prompted for creds.&lt;/P&gt;&lt;P&gt;Has anyone ran into this situation? Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most clients are using 3.1.3 while some are using 4.0.6. I am using aloways on mode and the same Kerberos profile to authenticat to both the portal and the gateway. I'm pretty sure that having them plug in their password twice is over-kill and adding to the issue. My security team would need some other way to auth to mitigate. I want to use pre-logon tunnel and device certs, but we just aren't there yet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or suggestions would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 16:47:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220192#M63533</guid>
      <dc:creator>Jonathan.Bennett</dc:creator>
      <dc:date>2018-07-02T16:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220200#M63534</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/17535"&gt;@Jonathan.Bennett&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Not sure what the solution would be, but the lockout should be temporary if you are following current recomendations as far as AD goes. The pre-logon with device cert auth would be the solution here as far as I'm aware, but the AD change would at least make it a little&amp;nbsp;&lt;EM&gt;less&lt;/EM&gt; of an issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 16:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220200#M63534</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-02T16:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220228#M63546</link>
      <description>&lt;P&gt;Ldap instead of kerberos would prevent account lockouts...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why not generate a cookie at portal login to use on gateway auth... to reduce prompts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 18:24:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220228#M63546</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-02T18:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220230#M63547</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know what MS recommendations are for AD, but our security team requires AD accounts to be manually unlocked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with you about the pre-logon tunnel, but it's another 6-8 months out for me. I was hoping to find a band-aid until then. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 18:54:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220230#M63547</guid>
      <dc:creator>Jonathan.Bennett</dc:creator>
      <dc:date>2018-07-02T18:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220232#M63549</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Will LDAP give a return like that? When I opened a case with PA TAC they told me it wouldn't. We've only used Radius for RSA and Kerberos, so I have not tested LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using a secure cookie would reduce a login prompt. Not sure if my security team will go for it, but it's idea. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 18:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220232#M63549</guid>
      <dc:creator>Jonathan.Bennett</dc:creator>
      <dc:date>2018-07-02T18:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220233#M63550</link>
      <description>&lt;P&gt;A return like what.... not sure what you mean...&amp;nbsp;&lt;/P&gt;&lt;P&gt;ldap just compares user vs password, just gets a yes or no, this is not registered against auth attempts on AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regarding cookies, i cannot see the benefit of using the same credentials twice, i can understand if using different auth profiles for portal and gateway but you seem not to be doing this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward to your portal config...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 19:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220233#M63550</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-02T19:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220237#M63551</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Looking forward to your portal config&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry.... wrong thread....&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 19:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220237#M63551</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-02T19:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect - Clients with excessive failed logins</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220239#M63552</link>
      <description>&lt;P&gt;I guess my ultimate wish would be to be able to get some sort of a error or message to the end user. Anything but a continual prompt for their creds. I have about 200 users on my portal, and I have about 15 that have multiple lock outs over the past 3 days.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jul 2018 19:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-clients-with-excessive-failed-logins/m-p/220239#M63552</guid>
      <dc:creator>Jonathan.Bennett</dc:creator>
      <dc:date>2018-07-02T19:56:02Z</dc:date>
    </item>
  </channel>
</rss>

