Upgrade to 5.0.11 = High Amount of Global Protect Failed Auths

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Upgrade to 5.0.11 = High Amount of Global Protect Failed Auths

L4 Transporter

We upgraded one of our 5020's from 4.1.13 to 5.0.11 about 2 weeks ago.  Ever since then, we have been seeing an unusually high number of failed auths from Global Protect.  Has anyone else experienced this?

The attached graph was made in Excel.  I used this filter in PA ( eventid eq globalprotectgateway-auth-fail ) and ( receive_time geq '2014/02/01 00:00:00' ) to grab all of the GP failed auths from the System log, then graphed it out.  You can clearly see when we performed the upgrade.  I  have verified that these extra failed auths are not coming from a single user(or even a few).  It's spread out across all users.  The weird thing is, we haven't had any complaints(yet) about Global Protect not working, it has also worked 100% of the time for myself.

Failed-Feb1-Feb24.JPG.jpg

3 REPLIES 3

L4 Transporter

Just to kinda help clarify, the graph depicts the date as right to left. The far right is before the upgrade, the left is after the upgrade.

L4 Transporter

Hello jambulo

Yes I see that the system logs indicate GP Auth failures, to know more information about each failure we can look at

less mp-log authd.log ( Click Shift + G to go down to the latest )

Here for each failure it would give the logs and a reason. If you can share logs of one such may be we can find more.

Thanks

L4 Transporter

jambulo maybe a pcap of a session with a failed auth and a successful auth combined with using the SSL private key and Wireshark can help unravel this too?

  • 2041 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!