<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Portal  brute-force attempts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258933#M73442</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I personally utilize our SIEM and the available MineMeld API to dynamically add indicators from the DoS logs pushed to the SIEM from the firewall. I'm not sure if MineMeld itself can read the log files from the firewall or not; however that would be possible through AutoFocus.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure what you mean by "Since we have users all over i cannnot block by IP"? Surely your organization would allow you to block a Public IP that is attempting to brute-force access to a VPN with internal access correct?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 27 Apr 2019 04:51:30 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-04-27T04:51:30Z</dc:date>
    <item>
      <title>GlobalProtect Portal  brute-force attempts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258700#M73361</link>
      <description>&lt;P&gt;How can i block IP trying to brute-force GP portal website. Below is a screenshot taken from system logs.&lt;/P&gt;&lt;P&gt;We are not using ssl decryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/19714i7248B22C14117CD8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 21:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258700#M73361</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2019-04-24T21:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal  brute-force attempts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258720#M73367</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just build out a security policy blocking access for that IP address, or if you don't want to deny it across the board utilize the 'negate-source' feature and specify this IP address in the security policy allowing access to your portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd recommend that you utilize something like MineMeld going forward so you can build a Blocklist dynamically and build out an associated deny security policy to block access on your firewall quickly and without committing&amp;nbsp;the configuration. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might also want to look into configuring DoS policies and a DoS rule to take care of these things automatically and make it so you get alerts when something like this happens going forward. This is an extremely underutilized, but very powerful, feature on the firewalls.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 02:15:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258720#M73367</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-25T02:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal  brute-force attempts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258877#M73417</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for the syggestions. Since we have users all over i cannot block by IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Minemeld option seems interesting and we already have it running. From what i understand Minemeld would fetch the IP's from logs and pull them into blocklist. If that is correct can you link me to an article how to do this.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 15:17:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258877#M73417</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2019-04-26T15:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal  brute-force attempts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258933#M73442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/56221"&gt;@raji_toor&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I personally utilize our SIEM and the available MineMeld API to dynamically add indicators from the DoS logs pushed to the SIEM from the firewall. I'm not sure if MineMeld itself can read the log files from the firewall or not; however that would be possible through AutoFocus.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure what you mean by "Since we have users all over i cannnot block by IP"? Surely your organization would allow you to block a Public IP that is attempting to brute-force access to a VPN with internal access correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Apr 2019 04:51:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-brute-force-attempts/m-p/258933#M73442</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-04-27T04:51:30Z</dc:date>
    </item>
  </channel>
</rss>

